Tagged “nvd”
CVEs tagged nvd, newest first.
25602 CVEsRSS
CVE-2026-92942High· 7.5PoCvm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call
vm2 before 3.11.7 (affected versions <= 3.11.6) does not enforce the VM({ timeout }) option on code executed outside the synchronous VM#run() call. The timeout only wraps the single call to _runScript() via doWithTimeout() in lib/vm.js, …
CVE-2026-92941Critical· 10.0PoCvm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities
vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls an…
CVE-2026-92940Critical· 10.0vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https')
vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but metho…
CVE-2026-92939Critical· 9.9PoCvm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed
vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, but its callable exports still execute with host-process au…
CVE-2026-92938Critical· 9.9PoCvm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']
vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. The module is wrapped with vm.readonly(), which prevents p…
CVE-2026-92937Critical· 10.0PoCvm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process
vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target w…
CVE-2026-92936Medium· 5.8PoCvm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting
vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can force the host-realm source transformer to throw a SyntaxError (for example by calling ev…
CVE-2026-92935Critical· 9.0vm2 is a sandbox for running untrusted Node.js code
vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'object' && requireOpts !== null`, so an array-shaped `require`…
CVE-2026-92934Critical· 9.0PoCvm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal
vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single exception handler traversal. Attackers can exploit cycle d…
CVE-2026-92933Medium· 5.8PoCvm2 is a sandbox for running untrusted Node.js code
vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered shallow copy (`Object.assign({}, util)` in `defaultBuiltinLoaderUtil`), and the deprecated …
CVE-2026-92879Medium· 4.3A security flaw has been discovered in vgmstream up to r2117
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is i…
CVE-2026-90986High· 7.1Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Real Time Statistics Pro <= 11.21 versions.
CVE-2026-90887High· 7.1Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
Unauthenticated Cross Site Scripting (XSS) in WP Inventory Manager <= 2.5.4 versions.
CVE-2026-89418High· 8.7PoCgoogle-protobuf contains an unbounded recursion when parsing unknown protobuf group fields
google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nested START_GROUP wire bytes to any Node.js service that calls the generated deserializeB…
CVE-2026-81829Medium· 5.3A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers
A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by AWS Application Load Balancers. When the AWS_ALB key provider is configured, the resolver constructs the key-fetch UR…
CVE-2026-81453Medium· 6.5Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A low privileged attacker with remote access could potentially ex…
CVE-2026-81443Medium· 6.4Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-s…
CVE-2026-81442High· 8.1Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Privilege Management vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information …
CVE-2026-80355Medium· 5.4Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote …
CVE-2026-78528Medium· 5.3Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions.
CVE-2026-78295High· 8.8Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in Xagio SEO <= 7.1.0.43 versions.
CVE-2026-78294Medium· 6.5Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions.
CVE-2026-74017Medium· 5.3Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
CVE-2026-74005Medium· 5.4Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions.
CVE-2026-74002Medium· 5.3Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions.
CVE-2026-74000Medium· 5.3Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
Contributor Broken Access Control in Simple Membership <= 4.8.2 versions.
CVE-2026-73999Medium· 5.4Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions.
CVE-2026-71568Medium· 5.3In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requires winning the race with bmctest itself, which reduces the attack window and significantly increases its complexity.
CVE-2026-66676Medium· 5.3Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions.
CVE-2026-66631High· 7.6Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.
Administrator SQL Injection in MC Woocommerce Wishlist <= 1.9.21 versions.