CWE-501 · 24 записей
Trust Boundary Violation
CVE этого класса
25 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2020-4077Эксплойта нет | Context isolation bypass via contextBridge in Electronelectronjs · electron · CWE-501 | Критическая9,9 | — | 1,0 % | 6 июл. 2020 г. |
39Наблюдать | CVE-2022-1799Эксплойта нет | Incorrect signature verification on Google play-services-basement in Google Play SDKgoogle · google play services software development kit · CWE-501 | Критическая9,8 | — | 0,3 % | 29 июл. 2022 г. |
36Наблюдать | CVE-2020-4076Эксплойта нет | Context isolation bypass via leaked cross-context objects in Electronelectronjs · electron · CWE-501 | Критическая9,0 | — | 0,4 % | 6 июл. 2020 г. |
35Наблюдать | CVE-2024-49050Эксплойта нет | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | Высокая8,8 | — | 1,2 % | 12 нояб. 2024 г. |
35Наблюдать | CVE-2026-44091Эксплойта нет | Creation of a new configuration by posting a malicious ID to MQTTphoenix contact · charx sec-3150 · CWE-501 | Высокая8,8 | — | 0,6 % | 30 июл. 2026 г. |
32Наблюдать | CVE-2024-23682Эксплойта нет | Artemis Java Test Sandbox Class Loading Escapels1intum · artemis java test sandbox · CWE-501 | Высокая8,2 | — | 0,4 % | 19 янв. 2024 г. |
32Наблюдать | GHSA-gfmx-pph7-g46xЭксплойта нет | OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intendnpm · openclaw · CWE-501 | Высокая8,0 | — | — | 9 апр. 2026 г. |
32Наблюдать | GHSA-hj55-9jmv-9jrjЭксплойта нет | Duplicate Advisory: Sandbox escape in Artemis Java Test SandboxMaven · de.tum.in.ase:artemis-java-test-sandbox · CWE-501 | Высокая8,2 | — | — | 19 янв. 2024 г. |
32Наблюдать | GHSA-jf56-mccx-5f3fЭксплойта нет | OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channelnpm · openclaw · CWE-501 | Высокая8,0 | — | — | 9 апр. 2026 г. |
31Наблюдать | CVE-2025-49714Эксплойта нет | Visual Studio Code Python Extension Remote Code Execution Vulnerabilitymicrosoft · python · CWE-501 | Высокая7,8 | — | 0,4 % | 8 июл. 2025 г. |
31Наблюдать | CVE-2026-33828Эксплойта нет | Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerabilitymicrosoft · windows 10 1607 · CWE-501 | Высокая7,8 | — | 0,3 % | 9 июн. 2026 г. |
31Наблюдать | CVE-2023-0627Эксплойта нет | Docker Desktop 4.11.x allows --no-windows-containers flag bypassdocker · docker desktop · CWE-501 | Высокая7,8 | — | 0,3 % | 25 сент. 2023 г. |
31Наблюдать | CVE-2026-62146Эксплойта нет | Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socketred hat · red hat openshift container platform 4 · CWE-501 | Высокая7,8 | — | — | Сегодня |
30Наблюдать | CVE-2026-25725Эксплойта нет | Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.jsonanthropic · claude code · CWE-501 | Высокая7,7 | — | 0,6 % | 6 февр. 2026 г. |
30Наблюдать | CVE-2023-28597Эксплойта нет | Improper trust boundary implementation for SMB in Zoom Clientszoom · rooms · CWE-501 | Высокая7,5 | — | 0,5 % | 27 мар. 2023 г. |
30Наблюдать | CVE-2025-14542Эксплойта нет | Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpointCWE-501 | Высокая7,5 | — | 0,3 % | 13 дек. 2025 г. |
27Наблюдать | CVE-2020-15096Эксплойта нет | Context isolation bypass via Promise in Electronelectronjs · electron · CWE-501 | Средняя6,8 | — | 0,8 % | 6 июл. 2020 г. |
27Наблюдать | CVE-2019-0035Эксплойта нет | Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumesjuniper · junos · CWE-501 | Средняя6,8 | — | 0,4 % | 10 апр. 2019 г. |
27Наблюдать | CVE-2022-20826Эксплойта нет | A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (cisco · adaptive security appliance software · CWE-501 | Средняя6,8 | — | 0,3 % | 15 нояб. 2022 г. |
26Наблюдать | CVE-2024-1725Эксплойта нет | Kubevirt-csi: persistentvolume allows access to hcp's root noderedhat · openshift container platform · CWE-501 | Средняя6,5 | — | 0,6 % | 7 мар. 2024 г. |
23Наблюдать | CVE-2024-20265Эксплойта нет | A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisccisco · cisco ios xe software · CWE-501 | Средняя5,9 | — | 0,2 % | 27 мар. 2024 г. |
22Наблюдать | CVE-2026-24153Эксплойта нет | NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.nvidia · jetson linux · CWE-501 | Средняя5,5 | — | 0,1 % | 31 мар. 2026 г. |
21Наблюдать | CVE-2026-65902Эксплойта нет | DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTagscure53 · dompurify · CWE-501 | Средняя5,3 | — | 0,4 % | 23 июл. 2026 г. |
17Наблюдать | CVE-2025-1118Эксплойта нет | Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabledred hat · red hat enterprise linux 10 · CWE-501 | Средняя4,4 | — | 0,3 % | 19 февр. 2025 г. |
10Наблюдать | CVE-2025-48938Эксплойта нет | Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Servercli · go-gh · CWE-501 | Низкая2,6 | — | 0,5 % | 30 мая 2025 г. |
- CVE-2020-407739Наблюдать
Context isolation bypass via contextBridge in Electron
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %electronjs · electron6 июл. 2020 г.
- CVE-2022-179939Наблюдать
Incorrect signature verification on Google play-services-basement in Google Play SDK
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %google · google play services software development kit29 июл. 2022 г.
- CVE-2020-407636Наблюдать
Context isolation bypass via leaked cross-context objects in Electron
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %electronjs · electron6 июл. 2020 г.
- CVE-2024-4905035Наблюдать
Visual Studio Code Python Extension Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %microsoft · python12 нояб. 2024 г.
- CVE-2026-4409135Наблюдать
Creation of a new configuration by posting a malicious ID to MQTT
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %phoenix contact · charx sec-315030 июл. 2026 г.
- CVE-2024-2368232Наблюдать
Artemis Java Test Sandbox Class Loading Escape
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %ls1intum · artemis java test sandbox19 янв. 2024 г.
- GHSA-gfmx-pph7-g46x32Наблюдать
OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intend
ВысокаяCVSS 8,0Эксплойта нетnpm · openclaw9 апр. 2026 г.
- GHSA-hj55-9jmv-9jrj32Наблюдать
Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox
ВысокаяCVSS 8,2Эксплойта нетMaven · de.tum.in.ase:artemis-java-test-sandbox19 янв. 2024 г.
- GHSA-jf56-mccx-5f3f32Наблюдать
OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel
ВысокаяCVSS 8,0Эксплойта нетnpm · openclaw9 апр. 2026 г.
- CVE-2025-4971431Наблюдать
Visual Studio Code Python Extension Remote Code Execution Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microsoft · python8 июл. 2025 г.
- CVE-2026-3382831Наблюдать
Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %microsoft · windows 10 16079 июн. 2026 г.
- CVE-2023-062731Наблюдать
Docker Desktop 4.11.x allows --no-windows-containers flag bypass
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %docker · docker desktop25 сент. 2023 г.
- CVE-2026-6214631Наблюдать
Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket
ВысокаяCVSS 7,8Эксплойта нетred hat · red hat openshift container platform 4Сегодня
- CVE-2026-2572530Наблюдать
Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %anthropic · claude code6 февр. 2026 г.
- CVE-2023-2859730Наблюдать
Improper trust boundary implementation for SMB in Zoom Clients
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %zoom · rooms27 мар. 2023 г.
- CVE-2025-1454230Наблюдать
Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpoint
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %13 дек. 2025 г.
- CVE-2020-1509627Наблюдать
Context isolation bypass via Promise in Electron
СредняяCVSS 6,8Эксплойта нетEPSS 1 %electronjs · electron6 июл. 2020 г.
- CVE-2019-003527Наблюдать
Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes
СредняяCVSS 6,8Эксплойта нетEPSS 0 %juniper · junos10 апр. 2019 г.
- CVE-2022-2082627Наблюдать
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (
СредняяCVSS 6,8Эксплойта нетEPSS 0 %cisco · adaptive security appliance software15 нояб. 2022 г.
- CVE-2024-172526Наблюдать
Kubevirt-csi: persistentvolume allows access to hcp's root node
СредняяCVSS 6,5Эксплойта нетEPSS 1 %redhat · openshift container platform7 мар. 2024 г.
- CVE-2024-2026523Наблюдать
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisc
СредняяCVSS 5,9Эксплойта нетEPSS 0 %cisco · cisco ios xe software27 мар. 2024 г.
- CVE-2026-2415322Наблюдать
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %nvidia · jetson linux31 мар. 2026 г.
- CVE-2026-6590221Наблюдать
DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags
СредняяCVSS 5,3Эксплойта нетEPSS 0 %cure53 · dompurify23 июл. 2026 г.
- CVE-2025-111817Наблюдать
Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled
СредняяCVSS 4,4Эксплойта нетEPSS 0 %red hat · red hat enterprise linux 1019 февр. 2025 г.
- CVE-2025-4893810Наблюдать
Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server
НизкаяCVSS 2,6Эксплойта нетEPSS 1 %cli · go-gh30 мая 2025 г.