VulnScope — package-centric CVE lookup- CRITICAL9.0CVE-2026-48150Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign
- LOW3.5Papra HTTP redirect bypass can lead to SSRF via webhook delivery system
- CRITICAL10.0DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
- CRITICAL9.6Vitest browser mode serves unsanitized otelCarrier query parameter as inline script
- CRITICAL9.8When Vitest UI server is listening, arbitrary file can be read and executed
- CRITICAL10.0NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
- CRITICAL9.8vm2 sandbox escape via JSPI-backed Promise `.finally()` species bypass
- CRITICAL10.0vm2 has a CVE-2023-37903 patch bypass: nesting:true without explicit require still allows full RCE
- CRITICAL10.0vm2 is Vulnerable to Sandbox Breakout Through Promise Species
- CRITICAL10.0vm2 has a Sandbox Escape issue
- LOW3.7Axios has a Patch Bypass: Proxy-Authorization Header Injection via Prototype Pollution — Incomplete Null-Prototype Fix
- CRITICAL9.1Yamcs Vulnerable to Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
- CRITICAL9.8Yamcs Vulnerable to Remote Code Execution via Mission Database algorithm override
- CRITICAL10.0LiquidJS is Vulnerable to Remote Code Execution
- CRITICAL9.1Yamcs Vulnerable to Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
- CRITICAL9.6OCI layer symlink escape → arbitrary host write
- CRITICAL10.0Read-only volume remount bypass via guest CAP_SYS_ADMIN
- LOW2.0NocoDB: OAuth Token Scope Not Enforced at ACL Layer Allows Scope Escalation
- CRITICAL10.0Malicious code in @beproduct/nestjs-auth (0.1.2 through 0.1.19) — Mini Shai-Hulud worm
- CRITICAL9.8EPSS 0.10%Turbo: Unexpected local code execution during Yarn Berry detection
- CRITICAL10.09router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
- CRITICAL9.6GlassFish's gadget handler is vulnerable to RCE
- CRITICAL9.1GlassFish's Administration Console is Vulnerable to RCE
- CRITICAL9.8Camel-CXF and Camel-Knative Message Header are Vulnerable to Injection via Missing Inbound Filtering
- CRITICAL9.8EPSS 0.08%vm2 Has a Sandbox Breakout Using Async Generator