VulnSea

CWE-693

CVEs classified under CWE-693, newest first.

243 CVEsRSS

CVE-2026-93606Critical· 10.0PoC
3d ago

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`

vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API that returns a host-realm Promise, the bridge's rejection sanitizer (hostPromiseSanitizeReject / makeSanitizedPromis…

Abyssalpatriksimek · vm2EPSS 0.52%via NVD
CVE-2026-93605Critical· 10.0
3d ago

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules

vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits child_process despite blocking other host-spawning modules. Attackers can require child_process and execute arbitrary co…

Midnightpatriksimek · vm2EPSS 0.38%via NVD
CVE-2026-86800Medium· 5.3
3d ago

The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification val…

The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification val…

SunlitEPSS 0.25%via NVD
CVE-2026-86796Medium· 5.3
3d ago

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attack…

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attack…

SunlitEPSS 0.25%via NVD
CVE-2026-54577Low· 2.0
4d ago

mport is the MidnightBSD Package Manager

mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted local_argv and local_argc values but passed the original argument entry to audit_package(). When an operator or automat…

SunlitMidnightBSD · mportEPSS 0.15%via NVD
CVE-2026-92962Low· 2.1PoC
4d ago

vm2 is a sandbox for running untrusted JavaScript

vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepareStackTrace function in lib/setup-sandbox.js builds its output array using prototype-walking index assignment (lines[l…

Twilightpatriksimek · vm2EPSS 0.17%via NVD
CVE-2026-92959High· 7.1
4d ago

vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM

vm2 before 3.11.8 does not fully enforce the allowAsync: false option in VM and NodeVM. While localPromise.prototype.then is replaced with a handler that throws 'Async not available', the sandbox's Promise static methods (Promise.resolve…

Twilightpatriksimek · vm2EPSS 0.26%via NVD
CVE-2026-92956Critical· 10.0
4d ago

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26

vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise th…

Midnightpatriksimek · vm2EPSS 0.40%via NVD
CVE-2026-92948Critical· 9.9PoC
4d ago

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the node:test builtin (e.g. require: { builtin: ['node:test']…

Abyssalpatriksimek · vm2EPSS 0.45%via NVD
CVE-2026-92944Critical· 9.8PoC
4d ago

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseThenLookupChain protector in V8 14.6. Attackers can exploi…

Abyssalpatriksimek · vm2EPSS 0.58%via NVD
CVE-2026-92938Critical· 9.9PoC
4d ago

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents p…

Abyssalpatriksimek · vm2EPSS 0.42%via NVD
CVE-2026-92934Critical· 9.0PoC
4d ago

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle d…

Abyssalpatriksimek · vm2EPSS 0.74%via NVD
CVE-2026-92778Medium· 5.4
5d ago

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate

CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers to bypass the feature gate. Attackers can access the form endpoints to start and stop the recurring election schedul…

Sunlityahoo · CMAKEPSS 0.32%via NVD
CVE-2026-79298High· 8.4PoC
5d ago

An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.

An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrary code via the BOOTia32.efi and a crafted cloak32.dat file on the ESP.

MidnightEPSS 0.19%via NVD
CVE-2026-20331Critical· 9.6
5d ago

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software en…

MidnightCisco · Cisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareEPSS 0.23%via NVD
CVE-2026-76825High· 8.4
5d ago

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment

RestrictedPython is a tool that helps define a subset of the Python language for accepting program input in a trusted environment. Prior to 8.4, RestrictedPython could allow a sandbox escape when a custom import policy or globals exposed…

Twilightzopefoundation · RestrictedPythonEPSS 0.57%via NVD
CVE-2026-77401Medium· 6.8
5d ago

Zope AccessControl provides a general security framework for use in Zope

Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map …

Sunlitzopefoundation · AccessControlEPSS 0.37%via NVD
CVE-2026-92129High· 7.5
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, incl…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically to a class at runtime, allowing attackers with permission to define and run sandboxed scripts, incl…

Twilightjenkins · script_securityEPSS 0.45%via NVD
CVE-2026-92124High· 8.8
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from a collection that a sandboxed script casts to another type but performs the cast on the collection…

Twilightjenkins · script_securityEPSS 0.58%via NVD
CVE-2026-92123High· 8.8
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, property and attribute accesses, and array accesses), allowing attackers with permission to define…

Twilightjenkins · script_securityEPSS 0.58%via NVD
CVE-2026-92122High· 8.8
5d ago

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an in…

Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxed script coerces a value to an interface, if the value inherits a method of the same name as an in…

Twilightjenkins · script_securityEPSS 0.61%via NVD
CVE-2026-58767Medium· 6.7
6d ago

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede…

Sunlitgoogle · androidEPSS 0.10%via NVD
CVE-2026-58766High· 7.8
6d ago

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no…

Twilightgoogle · androidEPSS 0.07%via NVD
CVE-2026-58765Medium· 6.7
6d ago

In GPU, there is a possible permission bypass due to a logic error in the code

In GPU, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-58755Medium· 6.7
6d ago

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code

In smmu_install_nested_ste of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not …

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-58747Medium· 6.7
6d ago

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code

In smmu_detach_dev of arm-smmu-v3.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exp…

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-58726Medium· 6.7
6d ago

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check

In FsmReleaseKey of fsm.c, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

Sunlitgoogle · androidEPSS 0.07%via NVD
CVE-2026-0187Medium· 6.7
6d ago

In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code

In gsa_sw_pk_hash_compare of image-auth-srv.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no…

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-0186Medium· 6.7
6d ago

In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code

In ac_init_one_sswrp of init.c, there is a possible escalation of privilege due to a logic error in the code. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for ex…

Sunlitgoogle · androidEPSS 0.08%via NVD
CVE-2026-0189High· 8.4
6d ago

In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code

In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for expl…

Twilightgoogle · androidEPSS 0.09%via NVD
CWE-693 vulnerabilities (CVEs) · VulnSea