CWE-501 · 25 records
Trust Boundary Violation
CVEs in this class
25 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2020-4077No exploit | Context isolation bypass via contextBridge in Electronelectronjs · electron · CWE-501 | Critical9.9 | — | 1.0% | Jul 6, 2020 |
39Monitor | CVE-2022-1799No exploit | Incorrect signature verification on Google play-services-basement in Google Play SDKgoogle · google play services software development kit · CWE-501 | Critical9.8 | — | 0.3% | Jul 29, 2022 |
36Monitor | CVE-2020-4076No exploit | Context isolation bypass via leaked cross-context objects in Electronelectronjs · electron · CWE-501 | Critical9.0 | — | 0.4% | Jul 6, 2020 |
35Monitor | CVE-2024-49050No exploit | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | High8.8 | — | 1.2% | Nov 12, 2024 |
35Monitor | CVE-2026-44091No exploit | Creation of a new configuration by posting a malicious ID to MQTTphoenix contact · charx sec-3150 · CWE-501 | High8.8 | — | 0.6% | Jul 30, 2026 |
32Monitor | CVE-2024-23682No exploit | Artemis Java Test Sandbox Class Loading Escapels1intum · artemis java test sandbox · CWE-501 | High8.2 | — | 0.4% | Jan 19, 2024 |
32Monitor | GHSA-gfmx-pph7-g46xNo exploit | OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intendnpm · openclaw · CWE-501 | High8.0 | — | — | Apr 9, 2026 |
32Monitor | GHSA-hj55-9jmv-9jrjNo exploit | Duplicate Advisory: Sandbox escape in Artemis Java Test SandboxMaven · de.tum.in.ase:artemis-java-test-sandbox · CWE-501 | High8.2 | — | — | Jan 19, 2024 |
32Monitor | GHSA-jf56-mccx-5f3fNo exploit | OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channelnpm · openclaw · CWE-501 | High8.0 | — | — | Apr 9, 2026 |
31Monitor | CVE-2025-49714No exploit | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | High7.8 | — | 0.4% | Jul 8, 2025 |
31Monitor | CVE-2026-33828No exploit | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-501 | High7.8 | — | 0.3% | Jun 9, 2026 |
31Monitor | CVE-2023-0627No exploit | Docker Desktop 4.11.x allows --no-windows-containers flag bypassdocker · docker desktop · CWE-501 | High7.8 | — | 0.3% | Sep 25, 2023 |
31Monitor | CVE-2026-62146Proof of concept | Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socketred hat · red hat openshift container platform 4 · CWE-501 | High7.8 | — | 0.1% | Sep 30, 2026 |
30Monitor | CVE-2026-25725No exploit | Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.jsonanthropic · claude code · CWE-501 | High7.7 | — | 0.7% | Feb 6, 2026 |
30Monitor | CVE-2023-28597No exploit | Improper trust boundary implementation for SMB in Zoom Clientszoom · rooms · CWE-501 | High7.5 | — | 0.5% | Mar 27, 2023 |
30Monitor | CVE-2025-14542No exploit | Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpointCWE-501 | High7.5 | — | 0.3% | Dec 13, 2025 |
27Monitor | CVE-2020-15096No exploit | Context isolation bypass via Promise in Electronelectronjs · electron · CWE-501 | Medium6.8 | — | 0.8% | Jul 6, 2020 |
27Monitor | CVE-2019-0035No exploit | Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumesjuniper · junos · CWE-501 | Medium6.8 | — | 0.4% | Apr 10, 2019 |
27Monitor | CVE-2022-20826No exploit | A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (cisco · adaptive security appliance software · CWE-501 | Medium6.8 | — | 0.3% | Nov 15, 2022 |
26Monitor | CVE-2024-1725No exploit | Kubevirt-csi: persistentvolume allows access to hcp's root noderedhat · openshift container platform · CWE-501 | Medium6.5 | — | 0.6% | Mar 7, 2024 |
23Monitor | CVE-2024-20265No exploit | A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisccisco · cisco ios xe software · CWE-501 | Medium5.9 | — | 0.2% | Mar 27, 2024 |
22Monitor | CVE-2026-24153No exploit | NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.nvidia · jetson linux · CWE-501 | Medium5.5 | — | 0.1% | Mar 31, 2026 |
21Monitor | CVE-2026-65902No exploit | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTagscure53 · dompurify · CWE-501 | Medium5.3 | — | 0.4% | Jul 23, 2026 |
17Monitor | CVE-2025-1118No exploit | Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabledred hat · red hat enterprise linux 10 · CWE-501 | Medium4.4 | — | 0.3% | Feb 19, 2025 |
10Monitor | CVE-2025-48938No exploit | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Servercli · go-gh · CWE-501 | Low2.6 | — | 0.5% | May 30, 2025 |
- CVE-2020-407739Monitor
Context isolation bypass via contextBridge in Electron
CriticalCVSS 9.9No exploitEPSS 1%electronjs · electronJul 6, 2020
- CVE-2022-179939Monitor
Incorrect signature verification on Google play-services-basement in Google Play SDK
CriticalCVSS 9.8No exploitEPSS 0%google · google play services software development kitJul 29, 2022
- CVE-2020-407636Monitor
Context isolation bypass via leaked cross-context objects in Electron
CriticalCVSS 9.0No exploitEPSS 0%electronjs · electronJul 6, 2020
- CVE-2024-4905035Monitor
Visual Studio Code Python Extension Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%microsoft · pythonNov 12, 2024
- CVE-2026-4409135Monitor
Creation of a new configuration by posting a malicious ID to MQTT
HighCVSS 8.8No exploitEPSS 1%phoenix contact · charx sec-3150Jul 30, 2026
- CVE-2024-2368232Monitor
Artemis Java Test Sandbox Class Loading Escape
HighCVSS 8.2No exploitEPSS 0%ls1intum · artemis java test sandboxJan 19, 2024
- GHSA-gfmx-pph7-g46x32Monitor
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intend
HighCVSS 8.0No exploitnpm · openclawApr 9, 2026
- GHSA-hj55-9jmv-9jrj32Monitor
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
HighCVSS 8.2No exploitMaven · de.tum.in.ase:artemis-java-test-sandboxJan 19, 2024
- GHSA-jf56-mccx-5f3f32Monitor
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
HighCVSS 8.0No exploitnpm · openclawApr 9, 2026
- CVE-2025-4971431Monitor
Visual Studio Code Python Extension Remote Code Execution Vulnerability
HighCVSS 7.8No exploitEPSS 0%microsoft · pythonJul 8, 2025
- CVE-2026-3382831Monitor
Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
HighCVSS 7.8No exploitEPSS 0%microsoft · windows 10 1607Jun 9, 2026
- CVE-2023-062731Monitor
Docker Desktop 4.11.x allows --no-windows-containers flag bypass
HighCVSS 7.8No exploitEPSS 0%docker · docker desktopSep 25, 2023
- CVE-2026-6214631Monitor
Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
HighCVSS 7.8Proof of conceptEPSS 0%red hat · red hat openshift container platform 4Sep 30, 2026
- CVE-2026-2572530Monitor
Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
HighCVSS 7.7No exploitEPSS 1%anthropic · claude codeFeb 6, 2026
- CVE-2023-2859730Monitor
Improper trust boundary implementation for SMB in Zoom Clients
HighCVSS 7.5No exploitEPSS 1%zoom · roomsMar 27, 2023
- CVE-2025-1454230Monitor
Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpoint
HighCVSS 7.5No exploitEPSS 0%Dec 13, 2025
- CVE-2020-1509627Monitor
Context isolation bypass via Promise in Electron
MediumCVSS 6.8No exploitEPSS 1%electronjs · electronJul 6, 2020
- CVE-2019-003527Monitor
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
MediumCVSS 6.8No exploitEPSS 0%juniper · junosApr 10, 2019
- CVE-2022-2082627Monitor
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (
MediumCVSS 6.8No exploitEPSS 0%cisco · adaptive security appliance softwareNov 15, 2022
- CVE-2024-172526Monitor
Kubevirt-csi: persistentvolume allows access to hcp's root node
MediumCVSS 6.5No exploitEPSS 1%redhat · openshift container platformMar 7, 2024
- CVE-2024-2026523Monitor
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisc
MediumCVSS 5.9No exploitEPSS 0%cisco · cisco ios xe softwareMar 27, 2024
- CVE-2026-2415322Monitor
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.
MediumCVSS 5.5No exploitEPSS 0%nvidia · jetson linuxMar 31, 2026
- CVE-2026-6590221Monitor
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
MediumCVSS 5.3No exploitEPSS 0%cure53 · dompurifyJul 23, 2026
- CVE-2025-111817Monitor
Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled
MediumCVSS 4.4No exploitEPSS 0%red hat · red hat enterprise linux 10Feb 19, 2025
- CVE-2025-4893810Monitor
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
LowCVSS 2.6No exploitEPSS 1%cli · go-ghMay 30, 2025