Pricing
Case studies
Login
Start trial
The leading open source vulnerability database
Instantly mitigate vulnerabilities in WordPress websites with Patchstack.
See pricing
Rated 4.9
Total
52,990
Mitigations
Mitigation rules
17,315
No official patch
13,369
In triage
1,425
Published soon
38
Stats
WordPress stats
Search
Everything
Vulnerabilities
Priority
CVSS
0
10
Mitigation available
Exploited
Clear filters
Affected software | Vulnerability
Risk
Disclosed
@nestjs/microservices
< 11.2.4
NPM: Nest: Remote process termination via a deeply nested microservice message pattern
7.5
5 hours ago
fast-uri
< 2.4.7
NPM: fast-uri vulnerable to inconsistent host case normalization via percent-encoded octets
4.8
5 hours ago
fast-uri
>= 4.1.3, < 4.1.5
NPM: fast-uri vulnerable to mailto header injection via percent-encoded field-name desynchronization
4.8
5 hours ago
@xhmikosr/decompress
<= 10.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
5 hours ago
decompress
<= 4.2.1
NPM: @xhmikosr/decompress: Path traversal via symlink chain
9.1
5 hours ago
ip-address
<= 10.7.0
NPM: ip-address: isInSubnet() and isHostInSubnet() compare addresses of different families as if they shared an address space, allowing an allowlist check to admit an address outside its range
6.3
5 hours ago
ip-address
<= 10.7.0
NPM: ip-address: Address6 builds a parse diagnostic proportional to the input with no length bound, allowing a single long string to stall or crash the process
6.3
5 hours ago
moment
>= 2.29.2, < 2.31.0
NPM: moment vulnerable to Path Traversal via crafted non-string locale name
5.9
5 hours ago
brace-expansion
< 1.1.21
NPM: brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU denial of service
5.3
5 hours ago
brace-expansion
< 1.1.20
NPM: brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
7.5
5 hours ago
brace-expansion
< 1.1.19
NPM: brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
7.5
5 hours ago
engine.io
>= 6.6.0, < 6.6.10
NPM: Socket.IO: Engine.IO Protocol Revision Mismatch DoS
7.5
5 hours ago
nodemailer
>= 9.1.0, < 10.0.9
NPM: Nodemailer: Quoted local-part can produce malformed envelope recipient through RFC 5322 comment parsing
5.3
5 hours ago
nodemailer
<= 10.0.5
NPM: Nodemailer: Quadratic backtracking in the addressparser free-text fallback allows remote denial of service
7.5
5 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: Duplicate ZIP entry names: getEntry() and extractAllTo() resolve to different content
5.9
5 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: getDataAsync() bypasses the maxOutputLength size guard enforced by the synchronous getData() path
5.3
5 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: Unhandled error event in async DEFLATE decompression crashes Node.js process (DoS)
7.5
5 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip: Decompression-bomb protection (fix for CVE-2026-39244) can be bypassed by declaring uncompressed size as 0
7.5
10 hours ago
adm-zip
<= 0.6.0
NPM: adm-zip extraction preserves SUID/SGID bits from untrusted ZIPs -> local privilege escalation
7.1
10 hours ago
nodemailer
< 10.0.2
NPM: Nodemailer: Nested structured recipient arrays bypass the parser depth limit and cause stack exhaustion DoS
5.9
10 hours ago
Load more
×
Advertisement