Wed, May 13 · 06:16 PM CDTCVE-2026-43997
10.0/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are various ways to use the host Object, to escape the sandbox, one example would be using HostObject.getOwnPropertySymbols to obtain Symbol(nodejs.util.inspect.custom). This vulnerability is fixed in 3.11.0.
CVECVE-2026-43997
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44005
10.0/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox writes into the underlying host objects with otherReflectSet() and otherReflectDefineProperty(), which lets attacker-controlled JavaScript running i
CVECVE-2026-44005
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44006
10.0/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
CVECVE-2026-44006
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-46595
10.0/10 · Must read/watchNVDvuln
Summary
Previously, CVE-2024-45337 fixed an authorization bypass for misused ssh server configurations; if any other type of callback is passed other than public key, then the source-address validation would be skipped.
CVECVE-2026-46595
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Tue, Jun 09 · 09:17 PM CDTCVE-2026-47938
10.0/10 · Must read/watchNVDvuln
Summary
Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitation of this issue does not require user interaction. Scope is changed.
CVECVE-2026-47938
SeverityCRITICAL
TypeUPDATED
PublishedTue, Jun 09 · 09:17 PM CDT
ModifiedThu, Aug 06 · 02:41 PM CDT
Mon, Apr 14 · 07:15 PM CDTCVE-2025-1782
9.9/10 · Must read/watchNVDvuln
Summary
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server user. This flaw requires the attacker to be authenticated with a valid user accoun
CVECVE-2025-1782
SeverityCRITICAL
TypeUPDATED
PublishedMon, Apr 14 · 07:15 PM CDT
ModifiedThu, Aug 06 · 03:26 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-43999
9.9/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the module builtin is allowed (including via the '*' wildcard). The module builtin exposes Node's Module._load(), which loads any module by name directly in the host context, completely bypassing vm2's builtin
CVECVE-2026-43999
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, Jan 28 · 04:16 PM CSTCVE-2025-61140
9.8/10 · Must read/watchNVDvuln
Summary
The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution.
CVECVE-2025-61140
SeverityCRITICAL
TypeUPDATED
PublishedWed, Jan 28 · 04:16 PM CST
ModifiedThu, Aug 06 · 01:16 PM CDT
Fri, Jul 10 · 10:16 PM CDTCVE-2026-10768
9.8/10 · Must read/watchNVDvuln
Summary
Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0 to 1.6.0.
CVECVE-2026-10768
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 10 · 10:16 PM CDT
ModifiedThu, Aug 06 · 03:08 PM CDT
Fri, Jul 10 · 10:16 PM CDTCVE-2026-12535
9.8/10 · Must read/watchNVDvuln
Summary
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This issue affects Formatter Field versions: from 0.0.0 to 2.0.0.
CVECVE-2026-12535
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 10 · 10:16 PM CDT
ModifiedThu, Aug 06 · 02:44 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44008
9.8/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via getter on the array prototype exposing objects of the wrong side into the sandbox. This can be used to get host objects and get the host Functi
CVECVE-2026-44008
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44009
9.8/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
CVECVE-2026-44009
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-45411
9.8/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the return function, the value is awaited on and exceptions thrown in the then call will be caught by the runtime and passed t
CVECVE-2026-45411
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, Apr 22 · 09:16 AM CDTCVE-2026-6235
9.8/10 · Must read/watchNVDvuln
Summary
The Sendmachine for WordPress plugin for WordPress is vulnerable to authorization bypass via the 'manage_admin_requests' function in all versions up to, and including, 1.0.20. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated atta
CVECVE-2026-6235
SeverityCRITICAL
TypeUPDATED
PublishedWed, Apr 22 · 09:16 AM CDT
ModifiedThu, Aug 06 · 10:18 PM CDT
Fri, Jul 10 · 09:17 PM CDTCVE-2026-9726
9.8/10 · Must read/watchNVDvuln
Summary
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This issue affects Drupal AlternativeCommerce (Basket) versions: from 0.0.0 to 2.1.17.
CVECVE-2026-9726
SeverityCRITICAL
TypeUPDATED
PublishedFri, Jul 10 · 09:17 PM CDT
ModifiedThu, Aug 06 · 06:28 PM CDT
Fri, May 22 · 04:16 PM CDTCVE-2026-39821
9.6/10 · Must read/watchNVDvuln
Summary
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a
CVECVE-2026-39821
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 PM CDT
ModifiedThu, Aug 06 · 01:17 PM CDT
Fri, Mar 20 · 11:16 PM CDTCVE-2026-33186
9.1/10 · Must read/watchNVDvuln
Summary
gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omitted the mandatory leading slash (e.g.,
CVECVE-2026-33186
SeverityCRITICAL
TypeUPDATED
PublishedFri, Mar 20 · 11:16 PM CDT
ModifiedThu, Aug 06 · 01:17 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-39830
9.1/10 · Must read/watchNVDvuln
Summary
A malicious SSH peer could send unsolicited global request responses to fill an internal buffer, blocking the connection's read loop. The blocked goroutine could not be released by calling Close(), resulting in a resource leak per connection. Unsolicited global responses are now discarded.
CVECVE-2026-39830
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Fri, May 22 · 04:16 AM CDTCVE-2026-42508
9.1/10 · Must read/watchNVDvuln
Summary
Previously, a revoked 'SignatureKey' belonging to a CA was not correctly checked for revocation. Now, both the 'key' and 'key.SignatureKey' are checked for @revoked.
CVECVE-2026-42508
SeverityCRITICAL
TypeUPDATED
PublishedFri, May 22 · 04:16 AM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Wed, May 13 · 06:16 PM CDTCVE-2026-44007
9.1/10 · Must read/watchNVDvuln
Summary
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require configuration — including require: false. With access to vm2, the sandbox constructs a new inner NodeVM with its own unrestrict
CVECVE-2026-44007
SeverityCRITICAL
TypeUPDATED
PublishedWed, May 13 · 06:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Mon, Aug 04 · 07:15 AM CDTCVE-2025-20701
8.8/10 · Worth your timeNVDvuln
Summary
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVE-2025-20701
SeverityHIGH
TypeUPDATED
PublishedMon, Aug 04 · 07:15 AM CDT
ModifiedThu, Aug 06 · 10:16 PM CDT
Thu, Mar 19 · 02:16 PM CDTCVE-2025-71260
8.8/10 · Worth your timeNVDvuln
Summary
BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain a deserialization of untrusted data vulnerability in the ASP.NET servlet's VIEWSTATE handling that allows authenticated attackers to execute arbitrary code. Attackers can supply crafted serialized objects to the VIEWSTATE parameter to achieve remote cod
CVECVE-2025-71260
SeverityHIGH
TypeUPDATED
PublishedThu, Mar 19 · 02:16 PM CDT
ModifiedThu, Aug 06 · 03:21 PM CDT
Mon, Apr 06 · 01:17 PM CDTCVE-2026-3524
8.8/10 · Worth your timeNVDvuln
Summary
Mattermost Plugin Legal Hold versions <=1.1.4 fail to halt request processing after a failed authorization check in ServeHTTP which allows an authenticated attacker to access, create, download, and delete legal hold data via crafted API requests to the plugin's endpoints. Mattermost Advisory ID: MMSA-2026-00621
CVECVE-2026-3524
SeverityHIGH
TypeUPDATED
PublishedMon, Apr 06 · 01:17 PM CDT
ModifiedThu, Aug 06 · 02:21 PM CDT
Thu, May 14 · 02:16 PM CDTCVE-2026-6477
8.8/10 · Worth your timeNVDvuln
Summary
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-large response. Like gets(), PQfn(..., result_is_int=0, ...) stores arbitrary-length
CVECVE-2026-6477
SeverityHIGH
TypeUPDATED
PublishedThu, May 14 · 02:16 PM CDT
ModifiedThu, Aug 06 · 01:18 PM CDT
Sun, Jun 28 · 12:16 AM CDTCVE-2026-10643
8.7/10 · Worth your timeNVDvuln
Summary
Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg->msg_controllen < pktinfo_len) before writing a full control message consisting of an aligned cmsg header plus the payload.
CVECVE-2026-10643
SeverityHIGH
TypeUPDATED
PublishedSun, Jun 28 · 12:16 AM CDT
ModifiedThu, Aug 06 · 10:16 PM CDT