CVE Tools

VM2

85 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for VM2, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

VM2 CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
VM2 CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-020
2026-030
2026-040
2026-0521
2026-069
2026-070
2026-085
2026-0937

Severity

How the 85 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical5267%
  • High1519%
  • Medium1114%

Latest CVEs

The 15 most recently published vulnerabilities affecting VM2.

  1. CVE-2026-100723vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool7.5
  2. CVE-2026-100722vm2 before 3.12.2 Host Process Termination via Construct Trap6.8
  3. CVE-2026-100721vm2 before 3.12.2 Authorization Bypass via Custom Resolver9.0
  4. CVE-2026-93606vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species10.0
  5. CVE-2026-93605vm2 NodeVM before 3.12.1 Remote Code Execution via child_process10.0
  6. CVE-2026-93604vm2 3.11.8 Sandbox Escape via crypto.setFips7.2
  7. CVE-2026-93603vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function10.0
  8. CVE-2026-92963vm2 before 3.11.2 Information Disclosure via Internal State5.3
  9. CVE-2026-92962vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js—
  10. CVE-2026-92961vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass7.5
  11. CVE-2026-92960vm2 before 3.11.6 Process-wide State Exposure via os and dns10.0
  12. CVE-2026-92959vm2 before 3.11.8 allowAsync Bypass via Promise Thenable7.1
  13. CVE-2026-92958vm2 before 3.11.7 Denylist Bypass via fs/promises8.5
  14. CVE-2026-92956vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming10.0
  15. CVE-2026-92957vm2 before 3.11.7 NodeVM Builtin Deny-List Bypass via node: Prefix9.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store