Vulnerabilities in patriksimek
74 resultsVexday analysis
Patriksimek apresenta 37 vulnerabilidades catalogadas, com 28 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Embora nenhuma esteja sob exploração ativa conhecida, 26 são críticas (70% do portfólio), predominantemente ligadas a problemas de proteção de mecanismos de segurança (CWE-693), representando risco significativo para ambientes em produção.
CVE-2026-93603CRITICALvm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host FunctionEPSS 0.4%CVE-2026-92960CRITICALvm2 before 3.11.6 Process-wide State Exposure via os and dnsEPSS 0.4%CVE-2026-92938CRITICALvm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqliteEPSS 0.4%CVE-2026-92952HIGHvm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering BypassEPSS 0.4%CVE-2026-44004HIGHvm2: Host Process OOM DoS via Buffer.alloc (Timeout Bypass)EPSS 0.4%CVE-2026-92936MEDIUMvm2 3.11.0 before 3.11.7 Information Disclosure via Error StackEPSS 0.4%CVE-2026-92956CRITICALvm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreamingEPSS 0.4%CVE-2026-47683HIGHvm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLikeEPSS 0.4%CVE-2026-93605CRITICALvm2 NodeVM before 3.12.1 Remote Code Execution via child_processEPSS 0.4%CVE-2026-47137CRITICALvm2: GHSA-8hg8-63c5-gwmx patch bypass: nesting:true without explicit require still allows full RCEEPSS 0.4%CVE-2026-47686CRITICALvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCEEPSS 0.4%CVE-2026-92961HIGHvm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit BypassEPSS 0.4%CVE-2026-92951CRITICALvm2 before 3.11.7 Module Allowlist Bypass via Custom ResolverEPSS 0.4%CVE-2026-92942HIGHvm2 before 3.11.7 Timeout Bypass via FinalizationRegistryEPSS 0.3%CVE-2026-92953CRITICALvm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArrayEPSS 0.3%CVE-2026-92954CRITICALvm2 3.10.0 through 3.11.5 Denial of Service via Host PromiseEPSS 0.3%CVE-2026-92940CRITICALvm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgentEPSS 0.3%CVE-2026-47141MEDIUMvm2: NodeVM observability builtins leak host process and HTTP request dataEPSS 0.3%CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.3%CVE-2026-47139HIGHvm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_serverEPSS 0.3%