Skip to content
Noroxi

CWE-501 · 25 records

Trust Boundary Violation

CVEs in this class

25 records

  • CVE-2020-4077
    39Monitor

    Context isolation bypass via contextBridge in Electron

    CriticalCVSS 9.9No exploitEPSS 1%

    electronjs · electronJul 6, 2020

  • CVE-2022-1799
    39Monitor

    Incorrect signature verification on Google play-services-basement in Google Play SDK

    CriticalCVSS 9.8No exploitEPSS 0%

    google · google play services software development kitJul 29, 2022

  • CVE-2020-4076
    36Monitor

    Context isolation bypass via leaked cross-context objects in Electron

    CriticalCVSS 9.0No exploitEPSS 0%

    electronjs · electronJul 6, 2020

  • Visual Studio Code Python Extension Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    microsoft · pythonNov 12, 2024

  • Creation of a new configuration by posting a malicious ID to MQTT

    HighCVSS 8.8No exploitEPSS 1%

    phoenix contact · charx sec-3150Jul 30, 2026

  • Artemis Java Test Sandbox Class Loading Escape

    HighCVSS 8.2No exploitEPSS 0%

    ls1intum · artemis java test sandboxJan 19, 2024

  • OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intend

    HighCVSS 8.0No exploit

    npm · openclawApr 9, 2026

  • Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

    HighCVSS 8.2No exploit

    Maven · de.tum.in.ase:artemis-java-test-sandboxJan 19, 2024

  • OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel

    HighCVSS 8.0No exploit

    npm · openclawApr 9, 2026

  • Visual Studio Code Python Extension Remote Code Execution Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    microsoft · pythonJul 8, 2025

  • Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability

    HighCVSS 7.8No exploitEPSS 0%

    microsoft · windows 10 1607Jun 9, 2026

  • CVE-2023-0627
    31Monitor

    Docker Desktop 4.11.x allows --no-windows-containers flag bypass

    HighCVSS 7.8No exploitEPSS 0%

    docker · docker desktopSep 25, 2023

  • Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket

    HighCVSS 7.8Proof of conceptEPSS 0%

    red hat · red hat openshift container platform 4Sep 30, 2026

  • Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json

    HighCVSS 7.7No exploitEPSS 1%

    anthropic · claude codeFeb 6, 2026

  • Improper trust boundary implementation for SMB in Zoom Clients

    HighCVSS 7.5No exploitEPSS 1%

    zoom · roomsMar 27, 2023

  • Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpoint

    HighCVSS 7.5No exploitEPSS 0%

    Dec 13, 2025

  • Context isolation bypass via Promise in Electron

    MediumCVSS 6.8No exploitEPSS 1%

    electronjs · electronJul 6, 2020

  • CVE-2019-0035
    27Monitor

    Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes

    MediumCVSS 6.8No exploitEPSS 0%

    juniper · junosApr 10, 2019

  • A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (

    MediumCVSS 6.8No exploitEPSS 0%

    cisco · adaptive security appliance softwareNov 15, 2022

  • CVE-2024-1725
    26Monitor

    Kubevirt-csi: persistentvolume allows access to hcp's root node

    MediumCVSS 6.5No exploitEPSS 1%

    redhat · openshift container platformMar 7, 2024

  • A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisc

    MediumCVSS 5.9No exploitEPSS 0%

    cisco · cisco ios xe softwareMar 27, 2024

  • NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.

    MediumCVSS 5.5No exploitEPSS 0%

    nvidia · jetson linuxMar 31, 2026

  • DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags

    MediumCVSS 5.3No exploitEPSS 0%

    cure53 · dompurifyJul 23, 2026

  • CVE-2025-1118
    17Monitor

    Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled

    MediumCVSS 4.4No exploitEPSS 0%

    red hat · red hat enterprise linux 10Feb 19, 2025

  • Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server

    LowCVSS 2.6No exploitEPSS 1%

    cli · go-ghMay 30, 2025

All vulnerability classes