Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-63472 | CRITICAL | 9.1 | Vendure is an open-source headless commerce platform. Prior to 3.7.0, ExternalAuthenticationService.createCustomerAndUser in packages/core/src/service/helpers/external-authentication/external-authentication.service.ts selects an existing customer user by emailAddress and attaches a newly presented … | Sep 17, 2026 |
| CVE-2026-63461 | MEDIUM | 5.3 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop API products, collections, and facets queries combine mandatory visibility guards with caller-supplied … | Sep 17, 2026 |
| CVE-2026-63460 | HIGH | 7.5 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern … | Sep 17, 2026 |
| CVE-2026-63459 | HIGH | 8.7 | Vendure is an open-source headless commerce platform. Prior to 3.6.5, RichTextDescriptionCell in packages/dashboard/src/lib/components/shared/table-cell/order-table-cell-components.tsx attempts to strip markup by assigning an administrator-controlled description to a live … | Sep 17, 2026 |
| CVE-2026-61793 | UNKNOWN | — | Nuxt OG Image generates OG Images with Vue templates in Nuxt. From 6.0.2 until 6.7.0, nuxt-og-image exposes the unauthenticated /_og/d/** route when the documented defaults … | Sep 17, 2026 |
| CVE-2026-54471 | LOW | 3.5 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileges vulnerability. A low privileged attacker with remote access could … | Sep 17, 2026 |
| CVE-2026-26950 | HIGH | 8.1 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Insufficient Verification of Data Authenticity vulnerability. A low privileged attacker with remote access could potentially exploit … | Sep 17, 2026 |
| CVE-2026-92973 | MEDIUM | 6.1 | ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL targets. Attackers controlling … | Sep 17, 2026 |
| CVE-2026-92972 | HIGH | 8.6 | SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allows attackers to poison the KV … | Sep 17, 2026 |
| CVE-2026-92971 | HIGH | 7.5 | InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attackers to terminate the inference engine. Attackers … | Sep 17, 2026 |
| CVE-2026-92970 | HIGH | 8.8 | HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write arbitrary files outside the … | Sep 17, 2026 |
| CVE-2026-92963 | MEDIUM | 5.3 | vm2 versions before 3.11.2 fail to properly restrict access to the VM2_INTERNAL_STATE_DO_NOT_USE_OR_PROGRAM_WILL_FAIL global variable. Attackers can access this internal state object through globalThis to retrieve … | Sep 17, 2026 |
| CVE-2026-92962 | UNKNOWN | — | vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array … | Sep 17, 2026 |
| CVE-2026-92961 | HIGH | 7.5 | vm2 before 3.11.6 fails to enforce bufferAllocLimit on ArrayBuffer, SharedArrayBuffer, and TypedArray constructors, allowing attackers to allocate arbitrary host memory. Attackers can bypass the buffer … | Sep 17, 2026 |
| CVE-2026-92960 | CRITICAL | 10.0 | vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity … | Sep 17, 2026 |
| CVE-2026-92959 | HIGH | 7.1 | vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async … | Sep 17, 2026 |
| CVE-2026-92958 | HIGH | 8.5 | vm2 through 3.11.6 contains a builtin-module denylist bypass in NodeVM. When the embedder uses the builtin wildcard together with negative entries (e.g. require: { builtin: … | Sep 17, 2026 |
| CVE-2026-92957 | CRITICAL | 9.9 | vm2 through 3.11.6 does not normalize `node:`-prefixed builtin specifiers when evaluating user-supplied negative (deny) entries in a NodeVM wildcard require policy. Although NodeVM strips the … | Sep 17, 2026 |
| CVE-2026-92956 | CRITICAL | 10.0 | vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can … | Sep 17, 2026 |
| CVE-2026-92955 | CRITICAL | 10.0 | vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can … | Sep 17, 2026 |
| CVE-2026-92954 | HIGH | 8.6 | vm2 is a sandbox library for running untrusted JavaScript in Node.js. In versions >= 3.10.0 and <= 3.11.7, Promises returned from the host realm into … | Sep 17, 2026 |
| CVE-2026-92953 | CRITICAL | 10.0 | vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and … | Sep 17, 2026 |
| CVE-2026-92952 | MEDIUM | 6.8 | vm2 versions 3.11.4 through 3.11.6 incompletely filter Node.js registered internal symbols across the sandbox boundary. The extraction filters in lib/setup-sandbox.js and the cross-realm symbol checks … | Sep 17, 2026 |
| CVE-2026-92951 | CRITICAL | 9.9 | vm2 before 3.11.7 contains an incorrect authorization vulnerability in the external package allowlist check that uses non-exact substring matching instead of full package-name boundary validation. … | Sep 17, 2026 |
| CVE-2026-92950 | HIGH | 8.6 | vm2 before 3.11.7 contains a sandbox escape vulnerability in the CLI tool that allows attackers to execute arbitrary code in the host Node.js process. Attackers … | Sep 17, 2026 |