Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

patriksimek — Vulnerabilities & Security Advisories 77

Browse all 77 CVE security advisories affecting patriksimek. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Patriksimek develops security tools and research, primarily focusing on vulnerability discovery and exploitation frameworks. Historically, their work has frequently involved remote code execution, cross-site scripting, and privilege escalation vulnerabilities across multiple platforms. Notable characteristics include contributions to penetration testing tools and disclosure of critical flaws in widely-used software. While no major security incidents directly attributed to patriksimek have been widely documented, their CVE record demonstrates consistent findings in high-impact vulnerabilities, particularly affecting web applications and system components. Their research often emphasizes practical exploitation techniques, making their findings relevant for both defensive security measures and penetration testing methodologies.

Top products by patriksimek: vm2
CVE ID Title CVSS Severity Published
CVE-2026-100723 vm2 before 3.12.2 Memory Disclosure via zlib Buffer Pool — vm2 CWE-200 7.5 High 2026-09-27
CVE-2026-100722 vm2 before 3.12.2 Host Process Termination via Construct Trap — vm2 CWE-248 6.8 Medium 2026-09-27
CVE-2026-100721 vm2 before 3.12.2 Authorization Bypass via Custom Resolver — vm2 CWE-863 9.0 Critical 2026-09-27
CVE-2026-93606 vm2 before 3.12.1 Sandbox Escape via Promise Symbol.species — vm2 CWE-693 10.0 Critical 2026-09-18
CVE-2026-93604 vm2 3.11.8 Sandbox Escape via crypto.setFips — vm2 CWE-284 7.2 High 2026-09-18
CVE-2026-93605 vm2 NodeVM before 3.12.1 Remote Code Execution via child_process — vm2 CWE-693 10.0 Critical 2026-09-18
CVE-2026-93603 vm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host Function — vm2 CWE-94 10.0 Critical 2026-09-18
CVE-2026-92963 vm2 before 3.11.2 Information Disclosure via Internal State — vm2 CWE-227 5.3 Medium 2026-09-17
CVE-2026-92961 vm2 before 3.11.6 Memory Exhaustion DoS via bufferAllocLimit Bypass — vm2 CWE-770 7.5 High 2026-09-17
CVE-2026-92962 vm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.js — vm2 CWE-693 2.1 Low 2026-09-17
CVE-2026-92960 vm2 before 3.11.6 Process-wide State Exposure via os and dns — vm2 CWE-200 10.0 Critical 2026-09-17
CVE-2026-92959 vm2 before 3.11.8 allowAsync Bypass via Promise Thenable — vm2 CWE-693 7.1 High 2026-09-17
CVE-2026-92958 vm2 before 3.11.7 Denylist Bypass via fs/promises — vm2 CWE-269 8.5 High 2026-09-17
CVE-2026-92957 vm2 before 3.11.7 NodeVM Builtin Deny-List Bypass via node: Prefix — vm2 CWE-269 9.9 Critical 2026-09-17
CVE-2026-92956 vm2 3.10.1 through 3.11.6 Sandbox Escape via WebAssembly.compileStreaming — vm2 CWE-693 10.0 Critical 2026-09-17
CVE-2026-92955 vm2 before 3.11.8 Sandbox Escape via NodeVM — vm2 CWE-913 10.0 Critical 2026-09-17
CVE-2026-92954 vm2 3.10.0 through 3.11.7 Denial of Service via Host Promise — vm2 CWE-248 8.6 High 2026-09-17
CVE-2026-92953 vm2 3.11.0 through 3.11.7 Prototype Pollution via TypedArray — vm2 CWE-913 10.0 Critical 2026-09-17
CVE-2026-92952 vm2 3.11.4 through 3.11.6 Sandbox Symbol Filtering Bypass — vm2 CWE-669 6.8 Medium 2026-09-17
CVE-2026-92951 vm2 before 3.11.7 Module Allowlist Bypass via Custom Resolver — vm2 CWE-706 9.9 Critical 2026-09-17
CVE-2026-92950 vm2 before 3.11.7 Sandbox Escape via CLI require — vm2 CWE-453 8.6 High 2026-09-17
CVE-2026-92949 vm2 3.9.6 before 3.11.7 Sandbox Bypass via Accessor Descriptor — vm2 CWE-471 4.0 Medium 2026-09-17
CVE-2026-92948 vm2 3.9.6 through 3.11.5 Sandbox Escape via node:test — vm2 CWE-693 9.9 Critical 2026-09-17
CVE-2026-92947 vm2 before 3.11.7 Memory Disclosure via Buffer Pool — vm2 CWE-200 10.0 Critical 2026-09-17
CVE-2026-92946 vm2 before 3.11.7 Remote Code Execution via require.external — vm2 CWE-913 10.0 Critical 2026-09-17
CVE-2026-92945 vm2 before 3.11.7 Module Allowlist Bypass via Prefix Matching — vm2 CWE-22 4.2 Medium 2026-09-17
CVE-2026-92942 vm2 before 3.11.7 Timeout Bypass via FinalizationRegistry — vm2 CWE-400 7.5 High 2026-09-17
CVE-2026-92944 vm2 3.10.2 through 3.11.6 Sandbox Escape via Promise Protector — vm2 CWE-693 9.8 Critical 2026-09-17
CVE-2026-92941 vm2 3.11.3 before 3.11.7 TLS Trust Store Manipulation — vm2 CWE-732 10.0 Critical 2026-09-17
CVE-2026-92940 vm2 3.11.3 through 3.11.6 HTTPS Credential Exposure via globalAgent — vm2 CWE-668 10.0 Critical 2026-09-17

This page lists every published CVE security advisory associated with patriksimek. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.