🔔 Premium Features
🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-92940 vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to a... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92939 vm2 3.11.3 through 3.11.6 exposes the host Node.js crypto module to a NodeVM sandbox when the crypto builtin is allowed. The module is presented via a... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92938 vm2 versions 3.11.3 through 3.11.6 expose Node.js's host node:sqlite module to code running in NodeVM when that builtin is permitted, either expl... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92937 vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomple... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92936 vm2 versions 3.11.0 through 3.11.6 leak absolute host filesystem paths to sandboxed code through error stack formatting. Attacker-supplied code can fo... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92935 vm2 is a sandbox for running untrusted Node.js code. In versions >= 3.11.4 and <= 3.11.6, the NodeVM constructor computes `hasRealRequireConfig`... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92934 vm2 before 3.11.8 contains an incomplete fix for Error.cause sanitization that allows sandbox escape when revisited host-wrapped AggregateError object... | CRITICAL | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92933 vm2 is a sandbox for running untrusted Node.js code. In versions <= 3.11.7, NodeVM exposes the host `util` module to the sandbox as an unfiltered s... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92973 ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scripting vulnerability in OSC 8 hyperlink handling that fails to validate or escape URL... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92972 SGLang through 0.5.19 in prefill/decode disaggregation mode contains an unauthenticated PUT /route endpoint on the prefill bootstrap service that allo... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92971 InternLM LMDeploy through 0.17.0 contains a reachable assertion vulnerability in the DistServe decode migration loop that allows unauthenticated attac... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-92970 HUBzero CMS through 2.2.32 contains a path traversal vulnerability in project file upload handlers that allows authenticated project members to write ... | HIGH | ????? | ????? | NVD | 5 days ago |
| CVE-2026-80355 Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerability. An unauthenticated attac... | MEDIUM | ????? | ????? | NVD | 5 days ago |
| CVE-2026-89418 google-protobuf contains an unbounded recursion when parsing unknown protobuf group fields. An attacker can send a small crafted payload of deeply nes... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-14850 The password reset funcionality is vulnerable to unauthorized account modification due to improper validation of the user_id parameter. An attacker ca... | UNKNOWN | ????? | ????? | NVD | 5 days ago |
| CVE-2026-90887 The WP Inventory Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.5.4. This is due to... | HIGH | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-78528 The BerqWP – All-In-One Optimization for Core Web Vitals, Cache, CDN, Images, CSS & JavaScript plugin for WordPress is vulnerable to unauthorize... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-78295 The Xagio SEO & AEO – AI SEO for Google Rankings & AI Visibility plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ver... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-78294 The Geo Mashup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.13.21. This is due to insuffi... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |
| CVE-2026-74017 The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &am... | MEDIUM | ????? | ????? | Wordfence | 5 days ago |