Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56576
Total
4483
Critical
16766
High
16609
Medium
CVE ID Severity Score Description Published
CVE-2026-63472 CRITICAL 9.1 Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented … Sep 17, 2026
CVE-2026-63461 MEDIUM 5.3 Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied … Sep 17, 2026
CVE-2026-63460 HIGH 7.5 Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern … Sep 17, 2026
CVE-2026-63459 HIGH 8.7 Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live … Sep 17, 2026
CVE-2026-61793 UNKNOWN — Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults … Sep 17, 2026
CVE-2026-54471 LOW 3.5 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could … Sep 17, 2026
CVE-2026-26950 HIGH 8.1 Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit … Sep 17, 2026
CVE-2026-92973 MEDIUM 6.1 ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling … Sep 17, 2026
CVE-2026-92972 HIGH 8.6 SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV … Sep 17, 2026
CVE-2026-92971 HIGH 7.5 InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers … Sep 17, 2026
CVE-2026-92970 HIGH 8.8 HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the … Sep 17, 2026
CVE-2026-92963 MEDIUM 5.3 vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve … Sep 17, 2026
CVE-2026-92962 UNKNOWN — vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array … Sep 17, 2026
CVE-2026-92961 HIGH 7.5 vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer … Sep 17, 2026
CVE-2026-92960 CRITICAL 10.0 vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity … Sep 17, 2026
CVE-2026-92959 HIGH 7.1 vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async … Sep 17, 2026
CVE-2026-92958 HIGH 8.5 vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: … Sep 17, 2026
CVE-2026-92957 CRITICAL 9.9 vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the … Sep 17, 2026
CVE-2026-92956 CRITICAL 10.0 vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can … Sep 17, 2026
CVE-2026-92955 CRITICAL 10.0 vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can … Sep 17, 2026
CVE-2026-92954 HIGH 8.6 vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into … Sep 17, 2026
CVE-2026-92953 CRITICAL 10.0 vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and … Sep 17, 2026
CVE-2026-92952 MEDIUM 6.8 vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks … Sep 17, 2026
CVE-2026-92951 CRITICAL 9.9 vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. … Sep 17, 2026
CVE-2026-92950 HIGH 8.6 vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers … Sep 17, 2026