Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
53,130
Mitigations
Mitigation rules
17,346
No official patch
13,360
In triage
1,356
Published soon
45
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@astrojs/node
<= 11.1.2
NPM: Astro: Malformed port in the Host header can crash the Node adapter
8.2
13 minutes ago
@angular/router
<= 19.2.25
NPM: Angular Server-Side Rendering (SSR): Denial of Service via Numeric URL Matrix Parameters
8.2
8 hours ago
serialize-javascript
>= 7.1.1, < 7.1.2
NPM: Serialize JavaScript: Cross-site scripting (XSS) via unescaped </script> in serialized function bodies
2.3
8 hours ago
Popular Posts
<= 7.4.2
Unauthenticated Information Disclosure in 'post_type' and 'context' Parameters vulnerability
5.3
8 hours ago
dompurify
>= 3.4.13, <= 3.4.15
NPM: DOMPurify: IN_PLACE: node-removing afterSanitize hook leaves detached subtree event handlers armed, causing DOM XSS
2.3
8 hours ago
@grpc/grpc-js
< 1.13.6
NPM: @grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
7.4
8 hours ago
@grpc/grpc-js
< 1.13.6
NPM: @grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
3.7
8 hours ago
axios
>= 1.0.0, < 1.20.0
NPM: Axios: Header Injection via Inherited headers After Minimal Interceptor
6.9
8 hours ago
axios
>= 1.12.0, < 1.20.0
NPM: Axios: Fetch Adapter Header Injection via Inherited FormData getHeaders
6.9
8 hours ago
axios
>= 1.15.2, < 1.20.0
NPM: Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
7.6
8 hours ago
axios
>= 1.15.0, < 1.20.0
NPM: Axios: CIDR-form NO_PROXY entries are ignored, causing proxy exclusion bypass for internal IP ranges
6.9
8 hours ago
axios
>= 1.17.0, < 1.20.0
NPM: Axios: maxRedirects: 0 is not enforced by the fetch adapter, allowing redirect-based SSRF
7
8 hours ago
axios
>= 1.7.0, < 1.20.0
NPM: Axios: Prototype pollution gadget in fetch adapter can alter outbound requests
6.9
8 hours ago
axios
>= 0.27.2, < 0.34.0
NPM: Axios: Prototype-Pollution Gadget in the Default Instance Allows Inherited Object.prototype.method to Override HTTP Method
6.9
8 hours ago
axios
>= 1.16.1, < 1.20.0
NPM: Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
8.2
8 hours ago
axios
>= 1.15.0, < 1.20.0
NPM: Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
8.2
8 hours ago
axios
>= 0.28.0, < 0.34.0
NPM: Axios: Prototype Pollution Gadget in axios toFormData Options
8.3
8 hours ago
axios
>= 1.13.0, < 1.20.0
NPM: Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
7
8 hours ago
axios
>= 1.13.0, < 1.20.0
NPM: Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
8.2
8 hours ago
next
>= 16.2.0, < 16.3.6
NPM: Next.js: Remote Code Execution in next/og ImageResponse
9.5
8 hours ago
Load more