Java Vulnerabilities

11 advisories affecting Java

11

Total CVEs

8

Critical

3

High

CVE-2026-26954

Mar 13, 2026

Critical (10.0)

SandboxJS is a JavaScript sandboxing library. Prior to 0.8.34, it is possible to obtain arrays containing Function, which allows escaping the sandbox. Given an array containing Function, and Object.fr...

Read Advisory

CVE-2026-32304

Mar 13, 2026

Critical (9.8)

Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to 3.0.14, the create_function(args, code) function passes both parameters directly to the Function ...

Read Advisory

CVE-2025-48611

Mar 10, 2026

Critical (10.0)

In DeviceId of DeviceId.java, there is a possible desync in persistence due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. ...

Read Advisory

CVE-2026-30887

Mar 10, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites...

Read Advisory

CVE-2026-0848

Mar 5, 2026

Critical (10.0)

NLTK versions <=3.9.2 are vulnerable to arbitrary code execution due to improper input validation in the StanfordSegmenter module. The module dynamically loads external Java .jar files without verific...

Read Advisory

CVE-2026-20131

Mar 4, 2026

Critical (10.0)

A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary Java code as root o...

Read Advisory

CVE-2024-31328

Mar 2, 2026

High (8.8)

In broadcastIntentLockedTraced of BroadcastController.java, there is a possible way to launch arbitrary activities from the background on the paired companion phone due to a logic error in the code. T...

Read Advisory

CVE-2025-48574

Mar 2, 2026

High (8.4)

In validateAddingWindowLw of DisplayPolicy.java, there is a possible way for an app to intercept drag-and-drop events due to a missing permission check. This could lead to local escalation of privileg...

Read Advisory

CVE-2026-27597

Feb 25, 2026

Critical (10.0)

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boundraries set by `@enclave-vm/core`, which can be use...

Read Advisory

CVE-2026-27574

Feb 21, 2026

Critical (9.9)

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's node:vm module (explicitly documented as not a secur...

Read Advisory

CVE-2026-2549

Feb 16, 2026

High (7.3)

A vulnerability has been found in zhanghuanhao LibrarySystem 图书馆管理系统 up to 1.1.1. This impacts an unknown function of the file BookController.java. The manipulation leads to improper access controls. ...

Read Advisory

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.