Vulnerabilidades em patriksimek

74 resultados
Análise Vexday

Patriksimek apresenta 37 vulnerabilidades catalogadas, com 28 publicadas nos últimos 90 dias, indicando ritmo acelerado de descobertas. Embora nenhuma esteja sob exploração ativa conhecida, 26 são críticas (70% do portfólio), predominantemente ligadas a problemas de proteção de mecanismos de segurança (CWE-693), representando risco significativo para ambientes em produção.

CVE-2026-92939CRITICALvm2 3.11.3 through 3.11.6 Native Code Execution via crypto.setEngineEPSS 0.6%CVE-2026-92938CRITICALvm2 3.11.3 through 3.11.6 Remote Code Execution via node:sqliteEPSS 0.6%CVE-2026-44007CRITICALvm2: nesting: true bypasses require: false, allowing sandbox escape to arbitrary OS command executionEPSS 0.6%CVE-2026-92956CRITICALvm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreamingEPSS 0.6%CVE-2026-47686CRITICALvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCEEPSS 0.6%CVE-2026-92957CRITICALvm2 before 3.11.7 Authentication Bypass via node: PrefixEPSS 0.6%CVE-2026-92951CRITICALvm2 before 3.11.7 Module Allowlist Bypass via Custom ResolverEPSS 0.5%CVE-2026-47683HIGHvm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLikeEPSS 0.5%CVE-2026-92961HIGHvm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit BypassEPSS 0.5%CVE-2026-47141MEDIUMvm2: NodeVM observability builtins leak host process and HTTP request dataEPSS 0.5%CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.5%CVE-2026-92953CRITICALvm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArrayEPSS 0.5%CVE-2026-47139HIGHvm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_serverEPSS 0.5%CVE-2026-92942HIGHvm2 before 3.11.7 Timeout Bypass via FinalizationRegistryEPSS 0.5%CVE-2026-92954CRITICALvm2 3.10.0 through 3.11.5 Denial of Service via Host PromiseEPSS 0.5%CVE-2026-92947CRITICALvm2 before 3.11.7 Memory Disclosure via Buffer PoolEPSS 0.5%CVE-2026-92940CRITICALvm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgentEPSS 0.5%CVE-2026-92960CRITICALvm2 before 3.11.6 Process-wide State Exposure via os and dnsEPSS 0.5%CVE-2026-92952HIGHvm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering BypassEPSS 0.5%CVE-2026-92936MEDIUMvm2 3.11.0 before 3.11.7 Information Disclosure via Error StackEPSS 0.5%