Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
56576
Total
4483
Critical
16766
High
16609
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-92949 | MEDIUM | 4.0 | vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() … | Sep 17, 2026 |
| CVE-2026-92948 | CRITICAL | 9.9 | vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer … | Sep 17, 2026 |
| CVE-2026-92947 | CRITICAL | 10.0 | vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code … | Sep 17, 2026 |
| CVE-2026-92946 | CRITICAL | 10.0 | vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's … | Sep 17, 2026 |
| CVE-2026-92945 | MEDIUM | 4.2 | vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted … | Sep 17, 2026 |
| CVE-2026-92944 | CRITICAL | 9.8 | vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector … | Sep 17, 2026 |
| CVE-2026-92942 | HIGH | 7.5 | vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout … | Sep 17, 2026 |
| CVE-2026-92941 | CRITICAL | 10.0 | vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. … | Sep 17, 2026 |
| CVE-2026-92940 | CRITICAL | 10.0 | vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin … | Sep 17, 2026 |
| CVE-2026-92939 | CRITICAL | 9.9 | vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via … | Sep 17, 2026 |
| CVE-2026-92938 | CRITICAL | 9.9 | vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: … | Sep 17, 2026 |
| CVE-2026-92937 | CRITICAL | 10.0 | vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the … | Sep 17, 2026 |
| CVE-2026-92936 | MEDIUM | 5.8 | vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer … | Sep 17, 2026 |
| CVE-2026-92935 | CRITICAL | 9.0 | vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === … | Sep 17, 2026 |
| CVE-2026-92934 | CRITICAL | 9.0 | vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception … | Sep 17, 2026 |
| CVE-2026-92933 | MEDIUM | 5.8 | vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered … | Sep 17, 2026 |
| CVE-2026-92879 | MEDIUM | 4.3 | A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in … | Sep 17, 2026 |
| CVE-2026-90986 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. | Sep 17, 2026 |
| CVE-2026-90887 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. | Sep 17, 2026 |
| CVE-2026-89418 | UNKNOWN | — | google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes … | Sep 17, 2026 |
| CVE-2026-86533 | UNKNOWN | — | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and … | Sep 17, 2026 |
| CVE-2026-86522 | UNKNOWN | — | Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing … | Sep 17, 2026 |
| CVE-2026-85500 | UNKNOWN | — | Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides … | Sep 17, 2026 |
| CVE-2026-82761 | UNKNOWN | — | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as … | Sep 17, 2026 |
| CVE-2026-82760 | UNKNOWN | — | Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API … | Sep 17, 2026 |