|
351
|
8.5 |
HIGH
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using filesystem symlinks, allowing sandboxed code to load modules from outside the all…
New
|
CWE-59
Link Following
|
CVE-2026-43998
|
2026-05-15 00:36 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
352
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
An authenticated remote code execution vulnerability exists in the AOS-8 and AOS-10 web-based management interface. A vulnerability in the certificate download functionality could allow an authentica…
New
|
NVD-CWE-noinfo
|
CVE-2026-44852
|
2026-05-15 00:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
353
|
7.2 |
HIGH
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object identity to cross into the sandbox through host Promise resolution. When a host-s…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-44000
|
2026-05-15 00:35 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
354
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Integer overflow or wraparound in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-34330
|
2026-05-15 00:27 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
355
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-34331
|
2026-05-15 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
356
|
8.0 |
HIGH
Network
|
microsoft
|
windows_server_2025
|
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-34332
|
2026-05-15 00:25 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
357
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-34333
|
2026-05-15 00:25 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
358
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-34334
|
2026-05-15 00:23 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
359
|
8.6 |
HIGH
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise construct…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-44001
|
2026-05-15 00:23 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
360
|
5.8 |
MEDIUM
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host ob…
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-44002
|
2026-05-15 00:23 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|