CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: Critical
10,000 result(s) · page 3 of 500
CVE-2026-92948
CRITICAL

vm2 versions >= 3.9.6 and <= 3.11.6 are affected by a NodeVM builtin allowlist bypass that permits a sandbox escape on Node.js 24 and newer when the embedder explicitly allows the ...

CVSS 9.9 2026-09-17
CVE-2026-92947
CRITICAL

vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed cod...

CVSS 10 2026-09-17
CVE-2026-92946
CRITICAL

vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can re...

CVSS 10 2026-09-17
CVE-2026-92944
CRITICAL

vm2 versions 3.10.2 through 3.11.6 contain a sandbox escape vulnerability on Node.js 26 where Promise.prototype.finally() bypasses vm2's wrapper protections due to a stale PromiseT...

CVSS 9.8 2026-09-17
CVE-2026-92941
CRITICAL

vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certifi...

CVSS 10 2026-09-17
CVE-2026-92940
CRITICAL

vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin ...

CVSS 10 2026-09-17
CVE-2026-92939
CRITICAL

vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a recursive read-only proxy, bu...

CVSS 9.9 2026-09-17
CVE-2026-92938
CRITICAL

vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either explicitly or through builtin: ['*']. T...

CVSS 9.9 2026-09-17
CVE-2026-92937
CRITICAL

vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bri...

CVSS 10 2026-09-17
CVE-2026-92935
CRITICAL

vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig` with `typeof requireOpts === 'objec...

CVSS 9 2026-09-17
CVE-2026-92934
CRITICAL

vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError objects are caught within a single e...

CVSS 9 2026-09-17
CVE-2026-86533
CRITICAL

Insufficient Session Expiration vulnerability in team-alembic AshAuthentication and AshAuthentication Phoenix allows a revoked session to remain fully authenticated. A resource co...

CVSS 9.1 2026-09-17
CVE-2026-85500
CRITICAL

Authentication Bypass by Primary Weakness vulnerability in team-alembic AshAuthentication allows an unconfirmed user to obtain a session, defeating a mandatory email confirmation r...

CVSS 9.1 2026-09-17
CVE-2026-82761
CRITICAL

Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in team-alembic AshAuthentication allows an attacker holding a leaked magic link to replay its single-use token and ...

CVSS 9.1 2026-09-17
CVE-2026-62108
CRITICAL

Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.

CVSS 9.8 2026-09-17
CVE-2026-62104
CRITICAL

Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.

CVSS 10 2026-09-17
CVE-2026-62101
CRITICAL

Unauthenticated Broken Authentication in EduAdmin Booking <= 5.4.2 versions.

CVSS 9.8 2026-09-17
CVE-2026-92860
CRITICAL

A security flaw has been discovered in rcourtman Pulse up to 6.0.4/6.1.0-rc.4. Affected by this issue is the function fmt.Sprintf of the file /api/security/quick-setup of the compo...

CVSS 9.1 2026-09-17
CVE-2026-90823
CRITICAL

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain a stack-based buffer overflow in /usr/sbin/auth_user_pass. An unauthenticat...

CVSS 9.8 2026-09-17
CVE-2026-90822
CRITICAL

FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthentic...

CVSS 9.8 2026-09-17
1 2 3 4 5 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.