CVE Vulnerability Database
Search and browse 397,994 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44578 | HIGH | 8.6 | 38.9% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-h... |
| CVE-2026-44009 | CRITICAL | 9.8 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2. |
| CVE-2026-44008 | CRITICAL | 9.8 | 0.9% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with obj... |
| CVE-2026-44007 | CRITICAL | 9.1 | 1.0% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code... |
| CVE-2026-44006 | CRITICAL | 10 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which... |
| CVE-2026-44005 | CRITICAL | 10 | 0.8% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r... |
| CVE-2026-44004 | HIGH | 7.5 | 0.4% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary ... |
| CVE-2026-44003 | MEDIUM | 5.8 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization tha... |
| CVE-2026-44002 | MEDIUM | 5.8 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper ... |
| CVE-2026-44001 | HIGH | 8.6 | 0.4% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any ... |
| CVE-2026-44000 | HIGH | 7.2 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object id... |
| CVE-2026-43999 | CRITICAL | 9.9 | 1.0% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul... |
| CVE-2026-43998 | HIGH | 8.5 | 0.7% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using fi... |
| CVE-2026-43997 | CRITICAL | 10 | 1.0% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are vario... |
| CVE-2026-0265 | HIGH | 8.1 | 0.4% | May 13, 2026 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with n... |
| CVE-2026-0264 | CRITICAL | 9.8 | 0.4% | May 13, 2026 | A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows a... |
| CVE-2026-0263 | CRITICAL | 9.8 | 0.3% | May 13, 2026 | A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated... |
| CVE-2026-0237 | HIGH | 7.8 | 0.1% | May 13, 2026 | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly ... |
| CVE-2026-44577 | MEDIUM | 5.9 | 0.7% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se... |
| CVE-2026-44576 | MEDIUM | 5.4 | 0.3% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica... |
| CVE-2026-44575 | HIGH | 7.5 | 1.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou... |
| CVE-2026-44574 | HIGH | 8.1 | 0.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica... |
| CVE-2026-44573 | HIGH | 7.5 | 0.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applica... |
| CVE-2026-2695 | MEDIUM | 6.3 | 0.2% | May 13, 2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premi... |
| CVE-2024-48519 | MEDIUM | 6.2 | 0.1% | May 13, 2026 | Buffer Overflow vulnerability in Ardupilot rover commit v.c56439b045162058df0ff136afea3081fcd06d38 allows a local attack... |
