CWE-653 · 63 записей
Improper Isolation or Compartmentalization
CVE этого класса
63 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
69На этой неделе | CVE-2025-1974Proof of concept | ingress-nginx admission controller RCE escalationkubernetes · ingress-nginx · CWE-653 | Критическая9,8 | — | 99,4 % | 24 мар. 2025 г. |
57В плане | CVE-2025-21590Готовый эксплойт | Junos OS: An local attacker with shell access can execute arbitrary codejuniper · junos · CWE-653 | Средняя6,7 | KEV | 1,7 % | 12 мар. 2025 г. |
40В плане | CVE-2026-4692Proof of concept | Sandbox escape in the Responsive Design Mode componentmozilla · firefox · CWE-653 | Критическая10,0 | — | 0,5 % | 24 мар. 2026 г. |
39Наблюдать | CVE-2026-53421Эксплойта нет | Apache Syncope: Remote Code Execution via Scripted Connectorapache · syncope · CWE-653 | Критическая9,8 | — | 1,1 % | 20 июл. 2026 г. |
39Наблюдать | CVE-2024-33768Эксплойта нет | lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.sammycage · lunasvg · CWE-653 | Критическая9,8 | — | 0,8 % | 30 апр. 2024 г. |
39Наблюдать | CVE-2026-63071Эксплойта нет | Apache Syncope: RCE via Groovy Sandbox bypassapache · syncope · CWE-653 | Критическая9,8 | — | 0,8 % | 20 июл. 2026 г. |
39Наблюдать | CVE-2026-53405Эксплойта нет | Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTaskapache · syncope · CWE-653 | Критическая9,8 | — | 0,7 % | 20 июл. 2026 г. |
39Наблюдать | CVE-2026-34775Эксплойта нет | Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectronjs · electron · CWE-653 | Критическая9,8 | — | 0,4 % | 3 апр. 2026 г. |
36Наблюдать | CVE-2026-0542Proof of concept | Remote Code Execution in ServiceNow AI Platformservicenow · servicenow ai platform · CWE-653 | Критическая9,2 | — | 0,6 % | 25 февр. 2026 г. |
36Наблюдать | CVE-2025-4083Эксплойта нет | Process isolation bypass using "javascript:" URI links in cross-origin framesmozilla · firefox · CWE-653 | Критическая9,1 | — | 0,5 % | 29 апр. 2025 г. |
35Наблюдать | CVE-2025-57738Эксплойта нет | Apache Syncope: Remote Code Execution by delegated administratorsapache · syncope · CWE-653 | Высокая7,2 | — | 23,2 % | 20 окт. 2025 г. |
35Наблюдать | CVE-2025-5476Эксплойта нет | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-653 | Высокая8,8 | — | 0,4 % | 20 июн. 2025 г. |
35Наблюдать | CVE-2026-40968Эксплойта нет | Spring gRPC SecurityContext leaks across requests on authorization failurevmware · spring grpc · CWE-653 | Высокая8,8 | — | 0,3 % | 28 апр. 2026 г. |
35Наблюдать | CVE-2024-20285Эксплойта нет | Cisco NX-OS Software Python Parser Escape Vulnerabilitycisco · nx-os · CWE-653 | Высокая8,8 | — | 0,2 % | 28 авг. 2024 г. |
34Наблюдать | CVE-2025-34201Эксплойта нет | Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instancesvasion · virtual appliance application · CWE-653 | Высокая8,5 | — | 0,3 % | 19 сент. 2025 г. |
33Наблюдать | CVE-2024-0136Эксплойта нет | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted codenvidia · nvidia container toolkit · CWE-653 | Высокая8,4 | — | 0,7 % | 27 янв. 2025 г. |
33Наблюдать | CVE-2026-65635Эксплойта нет | Boruta dynamic client registration allows creation of over-privileged OAuth clientsmalach-it · boruta · CWE-653 | Высокая8,3 | — | 0,5 % | 30 июл. 2026 г. |
33Наблюдать | CVE-2026-95699Эксплойта нет | MrSteam iSteamX Improper Isolation or Compartmentalizationmrsteam · isteamx application · CWE-653 | Высокая8,4 | — | 0,3 % | 6 дней назад |
32Наблюдать | CVE-2023-1305Эксплойта нет | Rapid7 InsightCloudSec box object accessrapid7 · insightappsec · CWE-653 | Высокая8,1 | — | 0,8 % | 21 мар. 2023 г. |
32Наблюдать | CVE-2025-12805Эксплойта нет | Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicyredhat · openshift ai · CWE-653 | Высокая8,1 | — | 0,4 % | 26 мар. 2026 г. |
32Наблюдать | CVE-2024-23683Эксплойта нет | Artemis Java Test Sandbox InvocationTargetException Subclass Escapels1intum · artemis java test sandbox · CWE-653 | Высокая8,2 | — | 0,4 % | 19 янв. 2024 г. |
31Наблюдать | CVE-2024-35281Эксплойта нет | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.fortinet · forticlient · CWE-653 | Высокая7,8 | — | 0,1 % | 13 мая 2025 г. |
30Наблюдать | CVE-2024-0135Эксплойта нет | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification onvidia · nvidia container toolkit · CWE-653 | Высокая7,6 | — | 1,1 % | 27 янв. 2025 г. |
30Наблюдать | CVE-2026-57135Эксплойта нет | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clientsmervinpraison · praisonai · CWE-653 | Высокая7,6 | — | 0,4 % | 15 сент. 2026 г. |
30Наблюдать | CVE-2024-47520Эксплойта нет | A user with advanced report application access rights can perform actions for which they are not authorizedarista · ng firewall · CWE-653 | Высокая7,6 | — | 0,4 % | 10 янв. 2025 г. |
- CVE-2025-197469На этой неделе
ingress-nginx admission controller RCE escalation
КритическаяCVSS 9,8Proof of conceptEPSS 99 %kubernetes · ingress-nginx24 мар. 2025 г.
- CVE-2025-2159057В плане
Junos OS: An local attacker with shell access can execute arbitrary code
СредняяCVSS 6,7KEVГотовый эксплойтEPSS 2 %juniper · junos12 мар. 2025 г.
- CVE-2026-469240В плане
Sandbox escape in the Responsive Design Mode component
КритическаяCVSS 10,0Proof of conceptEPSS 0 %mozilla · firefox24 мар. 2026 г.
- CVE-2026-5342139Наблюдать
Apache Syncope: Remote Code Execution via Scripted Connector
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · syncope20 июл. 2026 г.
- CVE-2024-3376839Наблюдать
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sammycage · lunasvg30 апр. 2024 г.
- CVE-2026-6307139Наблюдать
Apache Syncope: RCE via Groovy Sandbox bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · syncope20 июл. 2026 г.
- CVE-2026-5340539Наблюдать
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %apache · syncope20 июл. 2026 г.
- CVE-2026-3477539Наблюдать
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %electronjs · electron3 апр. 2026 г.
- CVE-2026-054236Наблюдать
Remote Code Execution in ServiceNow AI Platform
КритическаяCVSS 9,2Proof of conceptEPSS 1 %servicenow · servicenow ai platform25 февр. 2026 г.
- CVE-2025-408336Наблюдать
Process isolation bypass using "javascript:" URI links in cross-origin frames
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %mozilla · firefox29 апр. 2025 г.
- CVE-2025-5773835Наблюдать
Apache Syncope: Remote Code Execution by delegated administrators
ВысокаяCVSS 7,2Эксплойта нетEPSS 23 %apache · syncope20 окт. 2025 г.
- CVE-2025-547635Наблюдать
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sony · xav-ax8500 firmware20 июн. 2025 г.
- CVE-2026-4096835Наблюдать
Spring gRPC SecurityContext leaks across requests on authorization failure
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %vmware · spring grpc28 апр. 2026 г.
- CVE-2024-2028535Наблюдать
Cisco NX-OS Software Python Parser Escape Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cisco · nx-os28 авг. 2024 г.
- CVE-2025-3420134Наблюдать
Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %vasion · virtual appliance application19 сент. 2025 г.
- CVE-2024-013633Наблюдать
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %nvidia · nvidia container toolkit27 янв. 2025 г.
- CVE-2026-6563533Наблюдать
Boruta dynamic client registration allows creation of over-privileged OAuth clients
ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %malach-it · boruta30 июл. 2026 г.
- CVE-2026-9569933Наблюдать
MrSteam iSteamX Improper Isolation or Compartmentalization
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %mrsteam · isteamx application6 дней назад
- CVE-2023-130532Наблюдать
Rapid7 InsightCloudSec box object access
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %rapid7 · insightappsec21 мар. 2023 г.
- CVE-2025-1280532Наблюдать
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %redhat · openshift ai26 мар. 2026 г.
- CVE-2024-2368332Наблюдать
Artemis Java Test Sandbox InvocationTargetException Subclass Escape
ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %ls1intum · artemis java test sandbox19 янв. 2024 г.
- CVE-2024-3528131Наблюдать
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %fortinet · forticlient13 мая 2025 г.
- CVE-2024-013530Наблюдать
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification o
ВысокаяCVSS 7,6Эксплойта нетEPSS 1 %nvidia · nvidia container toolkit27 янв. 2025 г.
- CVE-2026-5713530Наблюдать
PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %mervinpraison · praisonai15 сент. 2026 г.
- CVE-2024-4752030Наблюдать
A user with advanced report application access rights can perform actions for which they are not authorized
ВысокаяCVSS 7,6Эксплойта нетEPSS 0 %arista · ng firewall10 янв. 2025 г.