Перейти к содержимому
Noroxi

CWE-501 · 24 записей

Trust Boundary Violation

CVE этого класса

25 записей

  • CVE-2020-4077
    39Наблюдать

    Context isolation bypass via contextBridge in Electron

    КритическаяCVSS 9,9Эксплойта нетEPSS 1 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2022-1799
    39Наблюдать

    Incorrect signature verification on Google play-services-basement in Google Play SDK

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    google · google play services software development kit29 июл. 2022 г.

  • CVE-2020-4076
    36Наблюдать

    Context isolation bypass via leaked cross-context objects in Electron

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2024-49050
    35Наблюдать

    Visual Studio Code Python Extension Remote Code Execution Vulnerability

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    microsoft · python12 нояб. 2024 г.

  • CVE-2026-44091
    35Наблюдать

    Creation of a new configuration by posting a malicious ID to MQTT

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    phoenix contact · charx sec-315030 июл. 2026 г.

  • CVE-2024-23682
    32Наблюдать

    Artemis Java Test Sandbox Class Loading Escape

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    ls1intum · artemis java test sandbox19 янв. 2024 г.

  • GHSA-gfmx-pph7-g46x
    32Наблюдать

    OpenClaw: Lower-trust background runtime output is injected into trusted `System:` events, and local async exec completion misses the intend

    ВысокаяCVSS 8,0Эксплойта нет

    npm · openclaw9 апр. 2026 г.

  • GHSA-hj55-9jmv-9jrj
    32Наблюдать

    Duplicate Advisory: Sandbox escape in Artemis Java Test Sandbox

    ВысокаяCVSS 8,2Эксплойта нет

    Maven · de.tum.in.ase:artemis-java-test-sandbox19 янв. 2024 г.

  • GHSA-jf56-mccx-5f3f
    32Наблюдать

    OpenClaw: Authenticated `/hooks/wake` and mapped `wake` payloads are promoted into the trusted `System:` prompt channel

    ВысокаяCVSS 8,0Эксплойта нет

    npm · openclaw9 апр. 2026 г.

  • CVE-2025-49714
    31Наблюдать

    Visual Studio Code Python Extension Remote Code Execution Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    microsoft · python8 июл. 2025 г.

  • CVE-2026-33828
    31Наблюдать

    Windows Device Health Attestation (DHA) Elevation of Privilege Vulnerability

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    microsoft · windows 10 16079 июн. 2026 г.

  • CVE-2023-0627
    31Наблюдать

    Docker Desktop 4.11.x allows --no-windows-containers flag bypass

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    docker · docker desktop25 сент. 2023 г.

  • CVE-2026-62146
    31Наблюдать

    Cri-o: cri-o: sandbox state poisoning via pod annotations may expose runtime socket

    ВысокаяCVSS 7,8Эксплойта нет

    red hat · red hat openshift container platform 4Сегодня

  • CVE-2026-25725
    30Наблюдать

    Claude Code Has Sandbox Escape via Persistent Configuration Injection in settings.json

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    anthropic · claude code6 февр. 2026 г.

  • CVE-2023-28597
    30Наблюдать

    Improper trust boundary implementation for SMB in Zoom Clients

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    zoom · rooms27 мар. 2023 г.

  • CVE-2025-14542
    30Наблюдать

    Command execution in python-utcp allows attackers to achieve remote code execution when fetching a remote Manual from a malicious endpoint

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    13 дек. 2025 г.

  • CVE-2020-15096
    27Наблюдать

    Context isolation bypass via Promise in Electron

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    electronjs · electron6 июл. 2020 г.

  • CVE-2019-0035
    27Наблюдать

    Junos OS: 'set system ports console insecure' allows root password recovery on OAM volumes

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    juniper · junos10 апр. 2019 г.

  • CVE-2022-20826
    27Наблюдать

    A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    cisco · adaptive security appliance software15 нояб. 2022 г.

  • CVE-2024-1725
    26Наблюдать

    Kubevirt-csi: persistentvolume allows access to hcp's root node

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    redhat · openshift container platform7 мар. 2024 г.

  • CVE-2024-20265
    23Наблюдать

    A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisc

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    cisco · cisco ios xe software27 мар. 2024 г.

  • CVE-2026-24153
    22Наблюдать

    NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled.

    СредняяCVSS 5,5Эксплойта нетEPSS 0 %

    nvidia · jetson linux31 мар. 2026 г.

  • CVE-2026-65902
    21Наблюдать

    DOMPurify before 3.4.7 Hook Mutation Pollution via allowedTags

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    cure53 · dompurify23 июл. 2026 г.

  • CVE-2025-1118
    17Наблюдать

    Grub2: commands/dump: the dump command is not in lockdown when secure boot is enabled

    СредняяCVSS 4,4Эксплойта нетEPSS 0 %

    red hat · red hat enterprise linux 1019 февр. 2025 г.

  • CVE-2025-48938
    10Наблюдать

    Prevent GitHub CLI and extensions from executing arbitrary commands from compromised GitHub Enterprise Server

    НизкаяCVSS 2,6Эксплойта нетEPSS 1 %

    cli · go-gh30 мая 2025 г.

Все классы уязвимостей