CWE-501 · 24 kayıt
Trust Boundary Violation
Bu sınıftaki CVE’ler
25 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2020-4077İstismar yok | Context isolation bypass via contextBridge in Electronelectronjs · electron · CWE-501 | Kritik9,9 | — | %1,0 | 6 Tem 2020 |
39İzleyin | CVE-2022-1799İstismar yok | Incorrect signature verification on Google play-services-basement in Google Play SDKgoogle · google play services software development kit · CWE-501 | Kritik9,8 | — | %0,3 | 29 Tem 2022 |
36İzleyin | CVE-2020-4076İstismar yok | Context isolation bypass via leaked cross-context objects in Electronelectronjs · electron · CWE-501 | Kritik9,0 | — | %0,4 | 6 Tem 2020 |
35İzleyin | CVE-2024-49050İstismar yok | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | Yüksek8,8 | — | %1,2 | 12 Kas 2024 |
35İzleyin | CVE-2026-44091İstismar yok | Creation of a new configuration by posting a malicious ID to MQTTphoenix contact · charx sec-3150 · CWE-501 | Yüksek8,8 | — | %0,6 | 30 Tem 2026 |
32İzleyin | CVE-2024-23682İstismar yok | Artemis Java Test Sandbox Class Loading Escapels1intum · artemis java test sandbox · CWE-501 | Yüksek8,2 | — | %0,4 | 19 Oca 2024 |
32İzleyin | GHSA-gfmx-pph7-g46xİstismar yok | OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intendnpm · openclaw · CWE-501 | Yüksek8,0 | — | — | 9 Nis 2026 |
32İzleyin | GHSA-hj55-9jmv-9jrjİstismar yok | Duplicate Advisory: Sandbox escape in Artemis Java Test SandboxMaven · de.tum.in.ase:artemis-java-test-sandbox · CWE-501 | Yüksek8,2 | — | — | 19 Oca 2024 |
32İzleyin | GHSA-jf56-mccx-5f3fİstismar yok | OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channelnpm · openclaw · CWE-501 | Yüksek8,0 | — | — | 9 Nis 2026 |
31İzleyin | CVE-2025-49714İstismar yok | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | Yüksek7,8 | — | %0,4 | 8 Tem 2025 |
31İzleyin | CVE-2026-33828İstismar yok | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-501 | Yüksek7,8 | — | %0,3 | 9 Haz 2026 |
31İzleyin | CVE-2023-0627İstismar yok | Docker Desktop 4.11.x allows --no-windows-containers flag bypassdocker · docker desktop · CWE-501 | Yüksek7,8 | — | %0,3 | 25 Eyl 2023 |
31İzleyin | CVE-2026-62146İstismar yok | Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socketred hat · red hat openshift container platform 4 · CWE-501 | Yüksek7,8 | — | — | Bugün |
30İzleyin | CVE-2026-25725İstismar yok | Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.jsonanthropic · claude code · CWE-501 | Yüksek7,7 | — | %0,6 | 6 Şub 2026 |
30İzleyin | CVE-2023-28597İstismar yok | Improper trust boundary implementation for SMB in Zoom Clientszoom · rooms · CWE-501 | Yüksek7,5 | — | %0,5 | 27 Mar 2023 |
30İzleyin | CVE-2025-14542İstismar yok | Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpointCWE-501 | Yüksek7,5 | — | %0,3 | 13 Ara 2025 |
27İzleyin | CVE-2020-15096İstismar yok | Context isolation bypass via Promise in Electronelectronjs · electron · CWE-501 | Orta6,8 | — | %0,8 | 6 Tem 2020 |
27İzleyin | CVE-2019-0035İstismar yok | Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumesjuniper · junos · CWE-501 | Orta6,8 | — | %0,4 | 10 Nis 2019 |
27İzleyin | CVE-2022-20826İstismar yok | A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (cisco · adaptive security appliance software · CWE-501 | Orta6,8 | — | %0,3 | 15 Kas 2022 |
26İzleyin | CVE-2024-1725İstismar yok | Kubevirt-csi: persistentvolume allows access to hcp's root noderedhat · openshift container platform · CWE-501 | Orta6,5 | — | %0,6 | 7 Mar 2024 |
23İzleyin | CVE-2024-20265İstismar yok | A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisccisco · cisco ios xe software · CWE-501 | Orta5,9 | — | %0,2 | 27 Mar 2024 |
22İzleyin | CVE-2026-24153İstismar yok | NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.nvidia · jetson linux · CWE-501 | Orta5,5 | — | %0,1 | 31 Mar 2026 |
21İzleyin | CVE-2026-65902İstismar yok | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTagscure53 · dompurify · CWE-501 | Orta5,3 | — | %0,4 | 23 Tem 2026 |
17İzleyin | CVE-2025-1118İstismar yok | Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabledred hat · red hat enterprise linux 10 · CWE-501 | Orta4,4 | — | %0,3 | 19 Şub 2025 |
10İzleyin | CVE-2025-48938İstismar yok | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Servercli · go-gh · CWE-501 | Düşük2,6 | — | %0,5 | 30 May 2025 |
- CVE-2020-407739İzleyin
Context isolation bypass via contextBridge in Electron
KritikCVSS 9,9İstismar yokEPSS %1electronjs · electron6 Tem 2020
- CVE-2022-179939İzleyin
Incorrect signature verification on Google play-services-basement in Google Play SDK
KritikCVSS 9,8İstismar yokEPSS %0google · google play services software development kit29 Tem 2022
- CVE-2020-407636İzleyin
Context isolation bypass via leaked cross-context objects in Electron
KritikCVSS 9,0İstismar yokEPSS %0electronjs · electron6 Tem 2020
- CVE-2024-4905035İzleyin
Visual Studio Code Python Extension Remote Code Execution Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %1microsoft · python12 Kas 2024
- CVE-2026-4409135İzleyin
Creation of a new configuration by posting a malicious ID to MQTT
YüksekCVSS 8,8İstismar yokEPSS %1phoenix contact · charx sec-315030 Tem 2026
- CVE-2024-2368232İzleyin
Artemis Java Test Sandbox Class Loading Escape
YüksekCVSS 8,2İstismar yokEPSS %0ls1intum · artemis java test sandbox19 Oca 2024
- GHSA-gfmx-pph7-g46x32İzleyin
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intend
YüksekCVSS 8,0İstismar yoknpm · openclaw9 Nis 2026
- GHSA-hj55-9jmv-9jrj32İzleyin
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
YüksekCVSS 8,2İstismar yokMaven · de.tum.in.ase:artemis-java-test-sandbox19 Oca 2024
- GHSA-jf56-mccx-5f3f32İzleyin
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
YüksekCVSS 8,0İstismar yoknpm · openclaw9 Nis 2026
- CVE-2025-4971431İzleyin
Visual Studio Code Python Extension Remote Code Execution Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0microsoft · python8 Tem 2025
- CVE-2026-3382831İzleyin
Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
YüksekCVSS 7,8İstismar yokEPSS %0microsoft · windows 10 16079 Haz 2026
- CVE-2023-062731İzleyin
Docker Desktop 4.11.x allows --no-windows-containers flag bypass
YüksekCVSS 7,8İstismar yokEPSS %0docker · docker desktop25 Eyl 2023
- CVE-2026-6214631İzleyin
Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
YüksekCVSS 7,8İstismar yokred hat · red hat openshift container platform 4Bugün
- CVE-2026-2572530İzleyin
Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
YüksekCVSS 7,7İstismar yokEPSS %1anthropic · claude code6 Şub 2026
- CVE-2023-2859730İzleyin
Improper trust boundary implementation for SMB in Zoom Clients
YüksekCVSS 7,5İstismar yokEPSS %1zoom · rooms27 Mar 2023
- CVE-2025-1454230İzleyin
Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpoint
YüksekCVSS 7,5İstismar yokEPSS %013 Ara 2025
- CVE-2020-1509627İzleyin
Context isolation bypass via Promise in Electron
OrtaCVSS 6,8İstismar yokEPSS %1electronjs · electron6 Tem 2020
- CVE-2019-003527İzleyin
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
OrtaCVSS 6,8İstismar yokEPSS %0juniper · junos10 Nis 2019
- CVE-2022-2082627İzleyin
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (
OrtaCVSS 6,8İstismar yokEPSS %0cisco · adaptive security appliance software15 Kas 2022
- CVE-2024-172526İzleyin
Kubevirt-csi: persistentvolume allows access to hcp's root node
OrtaCVSS 6,5İstismar yokEPSS %1redhat · openshift container platform7 Mar 2024
- CVE-2024-2026523İzleyin
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisc
OrtaCVSS 5,9İstismar yokEPSS %0cisco · cisco ios xe software27 Mar 2024
- CVE-2026-2415322İzleyin
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.
OrtaCVSS 5,5İstismar yokEPSS %0nvidia · jetson linux31 Mar 2026
- CVE-2026-6590221İzleyin
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
OrtaCVSS 5,3İstismar yokEPSS %0cure53 · dompurify23 Tem 2026
- CVE-2025-111817İzleyin
Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled
OrtaCVSS 4,4İstismar yokEPSS %0red hat · red hat enterprise linux 1019 Şub 2025
- CVE-2025-4893810İzleyin
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
DüşükCVSS 2,6İstismar yokEPSS %1cli · go-gh30 May 2025