Browse vulnerabilities

11 results

CVEPriorityEPSSCVSSKEVWhat
CVE-2026-43997 High 1.0% 10.0 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain th…
CVE-2026-43999 High 1.0% 9.9 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist …
CVE-2026-44007 High 1.0% 9.1 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created wi…
CVE-2026-44008 High 0.9% 9.8 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeAr…
CVE-2026-44005 High 0.8% 10.0 vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes m…
CVE-2026-44006 High 0.8% 10.0 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach Bas…
CVE-2026-44009 High 0.8% 9.8 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixe…
CVE-2026-45411 High 0.6% 9.8 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a h…
CVE-2026-43998 Medium 0.7% 8.5 vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restri…
CVE-2026-44001 Medium 0.4% 8.6 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerabil…
CVE-2026-44004 Medium 0.4% 7.5 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buf…