|
951
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-34331
|
2026-05-15 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
952
|
8.0 |
HIGH
Network
|
microsoft
|
windows_server_2025
|
Use after free in Windows Kernel-Mode Drivers allows an authorized attacker to execute code over a network.
Update
|
CWE-416
Use After Free
|
CVE-2026-34332
|
2026-05-15 00:25 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
953
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
Update
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-34333
|
2026-05-15 00:25 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
954
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362
Race Condition
|
CVE-2026-34334
|
2026-05-15 00:23 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
955
|
8.6 |
HIGH
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any sandboxed code to crash the host Node.js process via a single Promise construct…
New
|
CWE-248
Uncaught Exception
|
CVE-2026-44001
|
2026-05-15 00:23 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
956
|
5.8 |
MEDIUM
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper for V8's native CallSite) blocks getThis() and getFunction() to prevent host ob…
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-44002
|
2026-05-15 00:23 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
957
|
5.8 |
MEDIUM
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization that skips AST analysis when the code does not contain catch, import, or async key…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-44003
|
2026-05-15 00:22 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
958
|
7.5 |
HIGH
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary size to allocate memory directly on the host heap. Because Buffer.alloc is a sy…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-44004
|
2026-05-15 00:22 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
959
|
10.0 |
CRITICAL
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which can be used to get arbitrary prototypes. This vulnerability is fixed in 3.11.0.
New
|
CWE-94
Code Injection
|
CVE-2026-44006
|
2026-05-15 00:19 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
960
|
9.1 |
CRITICAL
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer VM's require config…
New
|
CWE-284
Improper Access Control
|
CVE-2026-44007
|
2026-05-15 00:18 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|