Перейти к содержимому
Noroxi

CWE-653 · 63 записей

Improper Isolation or Compartmentalization

CVE этого класса

63 записей

  • CVE-2025-1974
    69На этой неделе

    ingress-nginx admission controller RCE escalation

    КритическаяCVSS 9,8Proof of conceptEPSS 99 %

    kubernetes · ingress-nginx24 мар. 2025 г.

  • CVE-2025-21590
    57В плане

    Junos OS: An local attacker with shell access can execute arbitrary code

    СредняяCVSS 6,7KEVГотовый эксплойтEPSS 2 %

    juniper · junos12 мар. 2025 г.

  • CVE-2026-4692
    40В плане

    Sandbox escape in the Responsive Design Mode component

    КритическаяCVSS 10,0Proof of conceptEPSS 0 %

    mozilla · firefox24 мар. 2026 г.

  • CVE-2026-53421
    39Наблюдать

    Apache Syncope: Remote Code Execution via Scripted Connector

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · syncope20 июл. 2026 г.

  • CVE-2024-33768
    39Наблюдать

    lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sammycage · lunasvg30 апр. 2024 г.

  • CVE-2026-63071
    39Наблюдать

    Apache Syncope: RCE via Groovy Sandbox bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · syncope20 июл. 2026 г.

  • CVE-2026-53405
    39Наблюдать

    Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    apache · syncope20 июл. 2026 г.

  • CVE-2026-34775
    39Наблюдать

    Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    electronjs · electron3 апр. 2026 г.

  • CVE-2026-0542
    36Наблюдать

    Remote Code Execution in ServiceNow AI Platform

    КритическаяCVSS 9,2Proof of conceptEPSS 1 %

    servicenow · servicenow ai platform25 февр. 2026 г.

  • CVE-2025-4083
    36Наблюдать

    Process isolation bypass using "javascript:" URI links in cross-origin frames

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    mozilla · firefox29 апр. 2025 г.

  • CVE-2025-57738
    35Наблюдать

    Apache Syncope: Remote Code Execution by delegated administrators

    ВысокаяCVSS 7,2Эксплойта нетEPSS 23 %

    apache · syncope20 окт. 2025 г.

  • CVE-2025-5476
    35Наблюдать

    Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    sony · xav-ax8500 firmware20 июн. 2025 г.

  • CVE-2026-40968
    35Наблюдать

    Spring gRPC SecurityContext leaks across requests on authorization failure

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    vmware · spring grpc28 апр. 2026 г.

  • CVE-2024-20285
    35Наблюдать

    Cisco NX-OS Software Python Parser Escape Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    cisco · nx-os28 авг. 2024 г.

  • CVE-2025-34201
    34Наблюдать

    Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances

    ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %

    vasion · virtual appliance application19 сент. 2025 г.

  • CVE-2024-0136
    33Наблюдать

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code

    ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %

    nvidia · nvidia container toolkit27 янв. 2025 г.

  • CVE-2026-65635
    33Наблюдать

    Boruta dynamic client registration allows creation of over-privileged OAuth clients

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    malach-it · boruta30 июл. 2026 г.

  • CVE-2026-95699
    33Наблюдать

    MrSteam iSteamX Improper Isolation or Compartmentalization

    ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %

    mrsteam · isteamx application5 дней назад

  • CVE-2023-1305
    32Наблюдать

    Rapid7 InsightCloudSec box object access

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    rapid7 · insightappsec21 мар. 2023 г.

  • CVE-2025-12805
    32Наблюдать

    Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    redhat · openshift ai26 мар. 2026 г.

  • CVE-2024-23683
    32Наблюдать

    Artemis Java Test Sandbox InvocationTargetException Subclass Escape

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    ls1intum · artemis java test sandbox19 янв. 2024 г.

  • CVE-2024-35281
    31Наблюдать

    An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    fortinet · forticlient13 мая 2025 г.

  • CVE-2024-0135
    30Наблюдать

    NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification o

    ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %

    nvidia · nvidia container toolkit27 янв. 2025 г.

  • CVE-2026-57135
    30Наблюдать

    PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    mervinpraison · praisonai15 сент. 2026 г.

  • CVE-2024-47520
    30Наблюдать

    A user with advanced report application access rights can perform actions for which they are not authorized

    ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %

    arista · ng firewall10 янв. 2025 г.

Все классы уязвимостей