Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

56576
Total
4483
Critical
16766
High
16609
Medium
CVE ID Severity Score Description Published
CVE-2026-92949 MEDIUM 4.0 vm2 versions from 3.9.6 before 3.11.7 fail to properly restrict access to accessor properties on frozen objects, allowing sandboxed scripts to bypass vm.freeze() and vm.readonly() … Sep 17, 2026
CVE-2026-92948 CRITICAL 9.9 vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer … Sep 17, 2026
CVE-2026-92947 CRITICAL 10.0 vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code … Sep 17, 2026
CVE-2026-92946 CRITICAL 10.0 vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's … Sep 17, 2026
CVE-2026-92945 MEDIUM 4.2 vm2 before 3.11.7 contains a module allowlist bypass vulnerability in isPathAllowedForModule that uses raw string prefix matching instead of boundary-anchored comparison. Attackers can reach non-allowlisted … Sep 17, 2026
CVE-2026-92944 CRITICAL 9.8 vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector … Sep 17, 2026
CVE-2026-92942 HIGH 7.5 vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout … Sep 17, 2026
CVE-2026-92941 CRITICAL 10.0 vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. … Sep 17, 2026
CVE-2026-92940 CRITICAL 10.0 vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin … Sep 17, 2026
CVE-2026-92939 CRITICAL 9.9 vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via … Sep 17, 2026
CVE-2026-92938 CRITICAL 9.9 vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: … Sep 17, 2026
CVE-2026-92937 CRITICAL 10.0 vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the … Sep 17, 2026
CVE-2026-92936 MEDIUM 5.8 vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer … Sep 17, 2026
CVE-2026-92935 CRITICAL 9.0 vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === … Sep 17, 2026
CVE-2026-92934 CRITICAL 9.0 vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception … Sep 17, 2026
CVE-2026-92933 MEDIUM 5.8 vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered … Sep 17, 2026
CVE-2026-92879 MEDIUM 4.3 A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in … Sep 17, 2026
CVE-2026-90986 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions. Sep 17, 2026
CVE-2026-90887 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions. Sep 17, 2026
CVE-2026-89418 UNKNOWN — google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes … Sep 17, 2026
CVE-2026-86533 UNKNOWN — Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource configured with session_identifier :jti and … Sep 17, 2026
CVE-2026-86522 UNKNOWN — Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to forge application log entries by submitting a password reset identity containing … Sep 17, 2026
CVE-2026-85500 UNKNOWN — Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation requirement. AshAuthentication.Strategy.Password.Actions.check_user/2 decides … Sep 17, 2026
CVE-2026-82761 UNKNOWN — Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and authenticate as … Sep 17, 2026
CVE-2026-82760 UNKNOWN — Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and memory via an oversized base62 segment in a submitted API … Sep 17, 2026