Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-45411 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async g… Vm2 3.11.3+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-44005 vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 10.0 CVE-2026-44006 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-44008 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but … Vm2 3.11.2+ Fix from $2,3002026-05-13 CRITICAL 9.8 CVE-2026-44009 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. Vm2 3.11.2+ Fix from $2,3002026-05-13 CRITICAL 9.1 CVE-2026-44007 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require(… Vm2 3.11.1+ Fix from $2,3002026-05-13 HIGH 7.5 CVE-2026-44004 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory direc… Vm2 3.11.0+ Fix from $1,9502026-05-13 CRITICAL 10.0 CVE-2026-43997 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Objec… Vm2 3.11.0+ Fix from $2,3002026-05-13 CRITICAL 9.9 CVE-2026-43999 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (includi… Vm2 3.11.0+ Fix from $2,3002026-05-13 HIGH 8.6 CVE-2026-44001 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the h… Vm2 3.11.0+ Fix from $1,9502026-05-13 HIGH 8.5 CVE-2026-43998 vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing s… Vm2 No fix yet Fix from $1,9502026-05-13 HIGH 7.2 CVE-2026-44000 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sand… Vm2 3.11.0+ Fix from $1,9502026-05-13 MEDIUM 5.8 CVE-2026-44002 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blo… Vm2 3.11.0+ Fix from $1,6002026-05-13 MEDIUM 5.8 CVE-2026-44003 vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the… Vm2 3.11.0+ Fix from $1,6002026-05-13 CRITICAL 10.0 CVE-2026-26332 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code.… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-26956 vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker cod… Vm2 3.10.5+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24781 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24118 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to wr… Vm2 3.11.0+ Fix from $2,3002026-05-04 CRITICAL 9.8 CVE-2026-24120 vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing at… Vm2 3.10.5+ Fix from $2,3002026-05-04 CRITICAL 10.0 CVE-2026-22709 vm2 is an open source vm/sandbox for Node.js. In vm2 prior to version 3.10.2, `Promise.prototype.then` `Promise.prototype.catch` callback sanitizatio… Vm2 3.10.2+ Fix from $2,3002026-01-26 CRITICAL 10.0 CVE-2023-37903 vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to esc… Vm2 after 3.9.19 Fix from $2,3002023-07-21 CRITICAL 10.0 CVE-2023-37466 vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of th… Vm2 after 3.9.19 Fix from $2,3002023-07-14 CRITICAL 10.0 CVE-2023-32314EPSS 8% vm2 is a sandbox that can run untrusted code with Node's built-in modules. A sandbox escape vulnerability exists in vm2 for versions up to and includ… Vm2 3.9.18+ Fix from $2,3002023-05-15 MEDIUM 5.3 CVE-2023-32313 vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write re… Vm2 3.9.18+ Fix from $1,6002023-05-15 CRITICAL 10.0 CVE-2023-30547EPSS 72% vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. There exists a vulnerability in exception sanitization of vm2 … Vm2 after 3.9.16 Fix from $2,3002023-04-17 CRITICAL 10.0 CVE-2023-29199 There exists a vulnerability in source code transformer (exception sanitization logic) of vm2 for versions up to 3.9.15, allowing attackers to bypass… Vm2 3.9.16+ Fix from $2,3002023-04-14 CRITICAL 9.8 CVE-2023-29017EPSS 63% vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. Prior to version 3.9.15, vm2 was not properly handling host ob… Vm2 3.9.15+ Fix from $2,3002023-04-06 CRITICAL 9.8 CVE-2022-25893 The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. E… Vm2 3.9.10+ Fix from $2,3002022-12-21 CRITICAL 10.0 CVE-2022-36067EPSS 48% vm2 is a sandbox that can run untrusted code with whitelisted Node's built-in modules. In versions prior to version 3.9.11, a threat actor can bypass… Vm2 3.9.11+ Fix from $2,3002022-09-06 HIGH 8.3 CVE-2019-10761 This affects the package vm2 before 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by rea… Vm2 3.6.11+ Fix from $1,9502022-07-13