|
81
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM…
New
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24120
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…
New
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24118
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
New
|
CWE-416
Use After Free
|
CVE-2026-24082
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2025-47408
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-47407
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
New
|
CWE-126
Buffer Over-read
|
CVE-2025-47406
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2025-47405
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Memory corruption when dynamically changing the size of a previously allocated buffer while its contents are being modified.
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-47404
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Transient DOS when processing a malformed Fast Transition response frame with an invalid header structure during wireless roaming.
New
|
CWE-126
Buffer Over-read
|
CVE-2025-47403
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
Transient DOS when processing target power rate tables during channel configuration.
New
|
CWE-126
Buffer Over-read
|
CVE-2025-47401
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|