|
331
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.
New
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-26332
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
9.6 |
CRITICAL
Adjacent
|
-
|
-
|
Buffer overflow due to incorrect authorization in PLC FW
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-25293
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Memory corruption while processing IOCTL command when device is in power-save state.
New
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-25266
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can es…
New
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24781
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…
New
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24118
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory Corruption when copying data from a freed source while executing performance counter deselect operation.
New
|
CWE-416
Use After Free
|
CVE-2026-24082
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption when another driver calls an IOCTL with invalid input/output buffer.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2025-47408
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-47407
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Information Disclosure while processing IOCTL handler callbacks without verifying buffer size.
New
|
CWE-126
Buffer Over-read
|
CVE-2025-47406
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.8 |
HIGH
Local
|
-
|
-
|
Memory corruption when processing camera sensor input/output control codes with invalid output buffers.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2025-47405
|
2026-05-5 02:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|