Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
vm2 project vm2 vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-38834
easy-mock v1.5.0-v1.6.0 allows remote malicious users to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
Easy-mock Project Easy Mock
8.3
CVSSv3
CVE-2019-10761
This affects the package vm2 prior to 3.6.11. It is possible to trigger a RangeError exception from the host rather than the "sandboxed" context by reaching the stack call limit with an infinite recursion. The returned object is then used to reference the mainModule pro...
Vm2 Project Vm2
5.3
CVSSv3
CVE-2023-32313
vm2 is a sandbox that can run untrusted code with Node's built-in modules. In versions 3.9.17 and lower of vm2 it was possible to get a read-write reference to the node `inspect` method and edit options for `console.log`. As a result a threat actor can edit options for the `...
Vm2 Project Vm2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-5324
path traversal
CVE-2024-4743
CVE-2024-5184
TCP
CVE-2024-27822
code injection
CVE-2024-28995
CVE-2023-20938
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2