The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,714
Mitigations16,012
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
react-router>= 6.0.0, < 7.18.0
NPM: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass)
5.1
1 hour ago
react-router>= 7.9.6, <= 7.12.0
NPM: React Router: Open redirect leading to XSS
6.9
1 hour ago
react-router-dom>= 6.30.2, <= 6.30.4
NPM: React Router: Open redirect leading to XSS
6.9
1 hour ago
react-router>= 7.11.0, < 7.18.0
NPM: React Router: RSCErrorHandler Missing Protocol Validation (XSS)
6.9
1 hour ago
react-router>= 6.4.0, < 7.18.0
NPM: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration
6.1
1 hour ago
find-my-way<= 9.6.0
NPM: find-my-way: DDoS with HTTP2
7.5
1 hour ago
postcss<= 8.5.11
NPM: PostCSS: Arbitrary file read and information disclosure via attacker-controlled sourceMappingURL in CSS comments
7.5
6 hours ago
next-auth>= 5.0.0-beta.0, <= 5.0.0-beta.31
NPM: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)
9.1
6 hours ago
next-auth>= 4.0.6, <= 4.24.14
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
6 hours ago
@auth/core>= 0.1.0, < 0.41.3
NPM: Auth.js: getToken() throws an uncaught exception on malformed Bearer authorization headers
7.5
6 hours ago
next-auth>= 4.10.3, < 4.24.15
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
6 hours ago
@auth/core>= 0.1.0, < 0.41.3
NPM: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass
9.1
6 hours ago
next-auth<= 4.24.14
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
6 hours ago
@auth/core<= 0.41.2
NPM: Auth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created them
6.8
6 hours ago
n8n< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
22 hours ago
n8n< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
22 hours ago
n8n< 1.123.67
NPM: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
5.8
22 hours ago
next>= 14.1.1, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in Server Actions on custom servers
8.3
22 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies
6
22 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
6.3
22 hours ago