The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total53,718
Mitigations17,699
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
@simple-git/argv-parser< 2.0.1
NPM: simple-git: `VISUAL` editor environment variable is omitted from unsafe editor detection
9.2
4 hours ago
simple-git>= 3.15.0, < 4.0.1
NPM: simple-git unsafe-operation guard does not block trailer command configuration
9.2
4 hours ago
simple-git<= 3.36.0
NPM: simple-git allows command execution through unblocked Git configuration includes
8.1
4 hours ago
simple-git<= 3.36.0
NPM: simple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)
8.1
4 hours ago
@socket.io/cluster-engine< 0.1.1
NPM: Socket.IO: Prototype Pollution via Unsafe Client Session Lookup
7.5
4 hours ago
dompurify<= 3.4.15
NPM: DOMPurify: IN_PLACE returns a force-removed rawtext root whose text carries attacker markup — pure HTML reparse executes
0
4 hours ago
smol-toml<= 1.8.0
NPM: smol-toml: Quadratic-time parse() from parseKey rescanning to end of document on each key line
5.3
4 hours ago
katex>= 0.11.0, < 0.18.2
NPM: KaTeX: Existing prototype pollution can bypass trust restrictions
2.1
4 hours ago
seroval>= 0.12.0, <= 1.6.0
NPM: Seroval: `fromJSON()` Promise thenable assimilation invokes plugin-produced callables (bypass of GHSA-mv8w-475r-vwqw)
9.8
4 hours ago
seroval<= 1.6.2
NPM: Seroval: Memory exhaustion via unchecked TypedArray length in JSON deserialization
7.5
4 hours ago
proxy-addr>= 1.1.0, < 2.0.8
NPM: proxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnet
9.1
5 hours ago
@nx/docker>= 21.4.0, < 22.7.8
NPM: @nx/docker: OS command injection in the @nx/docker release pipeline
7.3
5 hours ago
nx>= 14.0.0, < 22.7.8
NPM: Nx: OS command injection via git revisions and remote refs
8.5
5 hours ago
nx>= 14.6.0, < 22.7.9
NPM: Nx daemon and plugin worker sockets are accessible to other local users
8.5
5 hours ago
nx>= 13.10.0, < 22.7.10
NPM: Nx: Path traversal in nx migrate package-migrations extraction
5.8
5 hours ago
compression< 1.8.2
NPM: compression vulnerable to Denial of Service via memory leak on premature response close
7.5
5 hours ago
@openclaw/googlechat< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
5 hours ago
@openclaw/matrix< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
5 hours ago
@openclaw/feishu< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
5 hours ago
@openclaw/msteams< 2026.8.1
NPM: OpenClaw: Channel read actions could skip target allowlists
6.5
5 hours ago