The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,741
Mitigations17,712
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
Deema Payment Gateway<= 1.1.2
Unauthenticated Payment Confirmation Forgery vulnerability
5.3
1 hour ago
Deema Payment Gateway<= 1.1.2
Unauthenticated Payment Bypass and Order Manipulation vulnerability
5.3
1 hour ago
JetElements For Elementor<= 2.9.2.2
Cross Site Scripting (XSS) vulnerability
6.5
2 hours ago
Slider Pro<= 1.0.0
Unauthenticated Sensitive Data Disclosure vulnerability
5.3
5 hours ago
File Media Renamer<= 1.3
Author+ Arbitrary File Rename vulnerability
6.5
5 hours ago
Fast Courier<= 5.2.3
Unauthenticated Order Fulfillment Update vulnerability
5.3
5 hours ago
@simple-git/argv-parser< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
11 hours ago
simple-git>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
11 hours ago
simple-git<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
11 hours ago
simple-git<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
11 hours ago
@socket.io/cluster-engine< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
11 hours ago
dompurify<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
11 hours ago
smol-toml<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
11 hours ago
katex>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
11 hours ago
seroval>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
11 hours ago
seroval<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
11 hours ago
proxy-addr>= 1.1.0, < 2.0.8
NPM: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
9.1
11 hours ago
@nx/docker>= 21.4.0, < 22.7.8
NPM: @nx/docker: OS command injection in the @nx/docker release pipeline
7.3
11 hours ago
nx>= 14.0.0, < 22.7.8
NPM: Nx: OS command injection via git revisions and remote refs
8.5
11 hours ago
nx>= 14.6.0, < 22.7.9
NPM: Nx daemon and plugin worker sockets are accessible to other local users
8.5
11 hours ago