VulnSea

CWE-913

CVEs classified under CWE-913, newest first.

18 CVEsRSS

CVE-2026-92955Critical· 10.0PoC
4d ago

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr

vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and tri…

Abyssalpatriksimek · vm2EPSS 0.62%via NVD
CVE-2026-92953Critical· 10.0PoC
4d ago

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation

vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype…

Abyssalpatriksimek · vm2EPSS 0.34%via NVD
CVE-2026-92946Critical· 10.0
4d ago

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted Node…

Midnightpatriksimek · vm2EPSS 0.59%via NVD
CVE-2026-92935Critical· 9.0
4d ago

vm2 is a sandbox for running untrusted Node.js code

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require`…

Midnightpatriksimek · vm2EPSS 0.50%via NVD
CVE-2026-90999Critical· 9.8
5d ago

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment

Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled telemetry to become code that is executed by an agent in a privileged automation environment. An external attacker can su…

MidnightFunctional Software, Inc. · Sentry SeerEPSS 0.51%via NVD
CVE-2026-92217Medium· 6.3
5d ago

A vulnerability was determined in a2ui-project a2ui up to 0.10.6

A vulnerability was determined in a2ui-project a2ui up to 0.10.6. This affects the function processMessages of the file renderers/web_core/src/v0_9/processing/message-processor.ts of the component Message Parsing. This manipulation cause…

Sunlita2ui-project · a2uiEPSS 0.32%via NVD
CVE-2026-12354High· 7.5
6d ago

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 through 9.3.5.1 CD, 9.4.0.0 through 9.4.0.25 LTS, 9.4.0.0 through 9.4.5.1 CD, and 10.0.0.0 could allow an authenticated attacker to …

TwilightIBM · MQEPSS 0.45%via NVD
CVE-2026-41870High· 8.8
1w ago

Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)

Missing Authorization, Improper Control of Generation of Code ('Code Injection'), Improper Control of Dynamically-Managed Code Resources, Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in…

TwilightApache Software Foundation · Apache NutchEPSS 0.69%via CVEORG
CVE-2026-65181High· 8.1
1w ago

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, w…

Insufficient authorization of Data Source tables in Impala 2.7-4.5 allows a client with privileges to upload a file to remote storage and create a table to execute arbitrary Java code. Users are recommended to upgrade to version 4.5.2, w…

Twilightapache · impalaEPSS 0.56%via NVD
CVE-2026-85408Medium· 4.3PoC
2w ago

A vulnerability was determined in Eleveo Quality Management 9.7.0

A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the component Conversation Handler. This manipulation of the argument create…

TwilightEleveo · Quality ManagementEPSS 0.23%via NVD
CVE-2026-48105High· 8.3
1mo ago

Arc is an open, SQL-native time-series database for telemetry

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:applyRegisterFile`) accepts attacker-chosen file paths in manifest-registration proposals w…

TwilightBasekick-Labs · arcEPSS 0.17%via NVD
CVE-2026-76023High· 8.8
1mo ago

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromi…

TwilightEPSS 0.46%via NVD
GHSA-9w56-46f6-3qhxMedium· 5.5
1mo ago

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

asteval Sandbox Escape: arbitrary native memory read/write via numpy ctypes in default asteval Interpreter

Sunlitasteval · astevalvia OSV
CVE-2026-47698Critical· 9.8
1mo ago

vm2 is an open source vm/sandbox for Node.js

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Function.prototype.call around dangerous host prototype getter and setter mutators, allowing …

Midnightvm2 · vm2EPSS 0.70%via NVD
CVE-2026-73226High· 8.8
1mo ago

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.15.186, electerm allows an authenticated WebSocket client to invoke unintended internal functions through client-controlled func values …

TwilightEPSS 0.39%via NVD
CVE-2026-48775Medium· 6.8
2mo ago

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

LangGraph Checkpoint: Unsafe JSON deserialization in checkpoint loading

Sunlitlanggraph-checkpoint · langgraph-checkpointEPSS 0.23%via GHSA
CVE-2026-53753Critical· 9.8PoC
3mo ago

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API

Abyssalcrawl4ai · crawl4aiEPSS 2.9%via GHSA
CVE-2026-34156Critical· 9.9PoC
5mo ago

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.28, NocoBase's Workflow Script Node executes user-supplied JavaScript inside a Node.js vm sandbox with …

Abyssalnocobase · nocobaseEPSS 35%via NVD
CWE-913 vulnerabilities (CVEs) · VulnSea