Skip to main content

CWE archive

CWE-1100 CVEs

Programmatic archive

4 CVEs tagged with CWE-11002 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-44008

Published May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with objects from the other side but can call into this side via ge…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-44007

Published May 13, 2026

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code can unconditionally require('vm2') regardless of the outer…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
39.0
Vendor/product tagsBeta · best-effort

CVE-2025-3466

Published Jul 7, 2025

langgenius/dify versions 1.1.0 to 1.1.2 are vulnerable to unsanitized input in the code node, allowing execution of arbitrary code with full root permissions. The vulnerability ar…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9612

Published Mar 20, 2025

In danswer-ai/danswer v0.3.94, administrators can set the visibility of pages within a workspace, including the search page. When the search page is set to be invisible, regular u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1