Browse vulnerabilities
11 results
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-43997 | High | 1.0% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain th… | |
| CVE-2026-43999 | High | 1.0% | 9.9 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist … | |
| CVE-2026-44007 | High | 1.0% | 9.1 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created wi… | |
| CVE-2026-44008 | High | 0.9% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeAr… | |
| CVE-2026-44005 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes m… | |
| CVE-2026-44006 | High | 0.8% | 10.0 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach Bas… | |
| CVE-2026-44009 | High | 0.8% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixe… | |
| CVE-2026-45411 | High | 0.6% | 9.8 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a h… | |
| CVE-2026-43998 | Medium | 0.7% | 8.5 | vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restri… | |
| CVE-2026-44001 | Medium | 0.4% | 8.6 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerabil… | |
| CVE-2026-44004 | Medium | 0.4% | 7.5 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buf… |