Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2269015
AlmaLinux
5992
Alpaquita
16124
Alpine
4635
Android
2912
Azure Linux
17766
BellSoft Hardened Containers
762
Bitnami
9492
Chainguard
1043084
CleanStart
5229
CRAN
14
crates.io
2747
Debian
68809
Docker Hardened Images
1
Echo
4007
GHC
3
GIT
107337
GitHub Actions
55
Go
9319
Hackage
33
Hex
364
Julia
1713
Linux
29269
Mageia
6233
Maven
7048
MinimOS
147541
npm
229052
NuGet
1869
opam
29
openEuler
8900
openSUSE
14530
OSS-Fuzz
4003
Packagist
7106
Pub
11
PyPI
25411
Red Hat
23452
Rocky Linux
4332
Root
19620
RubyGems
5326
SUSE
23400
SwiftURL
60
TuxCare
9676
Ubuntu
65814
VSCode
21
Wolfi
335914
ID
Packages
Summary
Published
arrow_upward
Attributes
MAL-2026-17423
npm/illusion-datalab
Malicious code in illusion-datalab (npm)
2 hours ago
No fix available
MAL-2026-17362
npm/@kelvdra/baileys
Malicious code in @kelvdra/baileys (npm)
8 hours ago
No fix available
MAL-2026-17351
npm/@bottino/baileys
Malicious code in @bottino/baileys (npm)
8 hours ago
No fix available
GHSA-jf8q-945g-9q4c
npm/vm2
vm2: Incomplete nodejs.* symbol filtering lets sandbox override host WebStream state checks
9 hours ago
Fix available
Severity - 6.8 (Medium)
GHSA-qhwx-74w5-xhxq
npm/vm2
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
9 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-jxxv-8r27-vm4p
npm/vm2
vm2 CLI provides no sandbox isolation - host-realm require() is reachable from sandboxed scripts
9 hours ago
Fix available
Severity - 8.6 (High)
GHSA-h85j-hv3c-qfgq
npm/vm2
vm2 exposes host HTTPS credentials and TLS traffic through globalAgent
9 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-c48m-32m9-vx93
npm/vm2
vm2 Custom Module Resolver Can Bypass the External Package Allowlist by Loading a Colliding Host Package
9 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-6rh5-qq4q-97xh
npm/vm2
vm2: NodeVM builtin denylist bypass via fs/promises despite -fs, allowing host filesystem writes
9 hours ago
Fix available
Severity - 8.5 (High)
GHSA-8686-vhfx-7r3j
npm/vm2
vm2: NodeVM node:-prefixed negative builtin deny bypass exposes child_process
9 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-633r-hq9m-c4ff
npm/vm2
vm2: vm.freeze()/vm.readonly() bypass via accessor descriptor
9 hours ago
Fix available
Severity - 4.0 (Medium)
GHSA-8hr7-r645-pc6w
npm/vm2
vm2: NodeVM nesting guard accepts array-shaped require and permits host RCE
9 hours ago
Fix available
Severity - 9.0 (Critical)
GHSA-647f-g98j-qq25
npm/vm2
vm2: GHSA-m283-3h24-438v fix bypass leads to host RCE via call/apply indirection
9 hours ago
Fix available
Severity - 10.0 (Critical)
GHSA-6w8r-xxw2-g3hx
npm/vm2
vm2 allows a sandboxed plugin to execute native code through `node:sqlite`
9 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-46pr-c5wc-xffx
npm/vm2
vm2 crypto builtin loads attacker native code through setEngine
9 hours ago
Fix available
Severity - 9.9 (Critical)
GHSA-27g9-p43v-cw3v
npm/vm2
vm2 sandbox escape on Node.js 26 through a stale PromiseThenLookupChain protector
9 hours ago
Fix available
Severity - 9.8 (Critical)
Load more...
npm - OSV