CWE-653 · 63 kayıt
Improper Isolation or Compartmentalization
Bu sınıftaki CVE’ler
63 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
69Bu hafta | CVE-2025-1974Kavram kanıtı | ingress-nginx admission controller RCE escalationkubernetes · ingress-nginx · CWE-653 | Kritik9,8 | — | %99,4 | 24 Mar 2025 |
57Planlayın | CVE-2025-21590Silahlaştırılmış | Junos OS: An local attacker with shell access can execute arbitrary codejuniper · junos · CWE-653 | Orta6,7 | KEV | %1,7 | 12 Mar 2025 |
40Planlayın | CVE-2026-4692Kavram kanıtı | Sandbox escape in the Responsive Design Mode componentmozilla · firefox · CWE-653 | Kritik10,0 | — | %0,5 | 24 Mar 2026 |
39İzleyin | CVE-2026-53421İstismar yok | Apache Syncope: Remote Code Execution via Scripted Connectorapache · syncope · CWE-653 | Kritik9,8 | — | %1,1 | 20 Tem 2026 |
39İzleyin | CVE-2024-33768İstismar yok | lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.sammycage · lunasvg · CWE-653 | Kritik9,8 | — | %0,8 | 30 Nis 2024 |
39İzleyin | CVE-2026-63071İstismar yok | Apache Syncope: RCE via Groovy Sandbox bypassapache · syncope · CWE-653 | Kritik9,8 | — | %0,8 | 20 Tem 2026 |
39İzleyin | CVE-2026-53405İstismar yok | Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTaskapache · syncope · CWE-653 | Kritik9,8 | — | %0,7 | 20 Tem 2026 |
39İzleyin | CVE-2026-34775İstismar yok | Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processeselectronjs · electron · CWE-653 | Kritik9,8 | — | %0,4 | 3 Nis 2026 |
36İzleyin | CVE-2026-0542Kavram kanıtı | Remote Code Execution in ServiceNow AI Platformservicenow · servicenow ai platform · CWE-653 | Kritik9,2 | — | %0,6 | 25 Şub 2026 |
36İzleyin | CVE-2025-4083İstismar yok | Process isolation bypass using "javascript:" URI links in cross-origin framesmozilla · firefox · CWE-653 | Kritik9,1 | — | %0,5 | 29 Nis 2025 |
35İzleyin | CVE-2025-57738İstismar yok | Apache Syncope: Remote Code Execution by delegated administratorsapache · syncope · CWE-653 | Yüksek7,2 | — | %23,2 | 20 Eki 2025 |
35İzleyin | CVE-2025-5476İstismar yok | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-653 | Yüksek8,8 | — | %0,4 | 20 Haz 2025 |
35İzleyin | CVE-2026-40968İstismar yok | Spring gRPC SecurityContext leaks across requests on authorization failurevmware · spring grpc · CWE-653 | Yüksek8,8 | — | %0,3 | 28 Nis 2026 |
35İzleyin | CVE-2024-20285İstismar yok | Cisco NX-OS Software Python Parser Escape Vulnerabilitycisco · nx-os · CWE-653 | Yüksek8,8 | — | %0,2 | 28 Ağu 2024 |
34İzleyin | CVE-2025-34201İstismar yok | Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instancesvasion · virtual appliance application · CWE-653 | Yüksek8,5 | — | %0,3 | 19 Eyl 2025 |
33İzleyin | CVE-2024-0136İstismar yok | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted codenvidia · nvidia container toolkit · CWE-653 | Yüksek8,4 | — | %0,7 | 27 Oca 2025 |
33İzleyin | CVE-2026-65635İstismar yok | Boruta dynamic client registration allows creation of over-privileged OAuth clientsmalach-it · boruta · CWE-653 | Yüksek8,3 | — | %0,5 | 30 Tem 2026 |
33İzleyin | CVE-2026-95699İstismar yok | MrSteam iSteamX Improper Isolation or Compartmentalizationmrsteam · isteamx application · CWE-653 | Yüksek8,4 | — | %0,3 | 5 gün önce |
32İzleyin | CVE-2023-1305İstismar yok | Rapid7 InsightCloudSec box object accessrapid7 · insightappsec · CWE-653 | Yüksek8,1 | — | %0,8 | 21 Mar 2023 |
32İzleyin | CVE-2025-12805İstismar yok | Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicyredhat · openshift ai · CWE-653 | Yüksek8,1 | — | %0,4 | 26 Mar 2026 |
32İzleyin | CVE-2024-23683İstismar yok | Artemis Java Test Sandbox InvocationTargetException Subclass Escapels1intum · artemis java test sandbox · CWE-653 | Yüksek8,2 | — | %0,4 | 19 Oca 2024 |
31İzleyin | CVE-2024-35281İstismar yok | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.fortinet · forticlient · CWE-653 | Yüksek7,8 | — | %0,1 | 13 May 2025 |
30İzleyin | CVE-2024-0135İstismar yok | NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification onvidia · nvidia container toolkit · CWE-653 | Yüksek7,6 | — | %1,1 | 27 Oca 2025 |
30İzleyin | CVE-2026-57135İstismar yok | PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clientsmervinpraison · praisonai · CWE-653 | Yüksek7,6 | — | %0,4 | 15 Eyl 2026 |
30İzleyin | CVE-2024-47520İstismar yok | A user with advanced report application access rights can perform actions for which they are not authorizedarista · ng firewall · CWE-653 | Yüksek7,6 | — | %0,4 | 10 Oca 2025 |
- CVE-2025-197469Bu hafta
ingress-nginx admission controller RCE escalation
KritikCVSS 9,8Kavram kanıtıEPSS %99kubernetes · ingress-nginx24 Mar 2025
- CVE-2025-2159057Planlayın
Junos OS: An local attacker with shell access can execute arbitrary code
OrtaCVSS 6,7KEVSilahlaştırılmışEPSS %2juniper · junos12 Mar 2025
- CVE-2026-469240Planlayın
Sandbox escape in the Responsive Design Mode component
KritikCVSS 10,0Kavram kanıtıEPSS %0mozilla · firefox24 Mar 2026
- CVE-2026-5342139İzleyin
Apache Syncope: Remote Code Execution via Scripted Connector
KritikCVSS 9,8İstismar yokEPSS %1apache · syncope20 Tem 2026
- CVE-2024-3376839İzleyin
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
KritikCVSS 9,8İstismar yokEPSS %1sammycage · lunasvg30 Nis 2024
- CVE-2026-6307139İzleyin
Apache Syncope: RCE via Groovy Sandbox bypass
KritikCVSS 9,8İstismar yokEPSS %1apache · syncope20 Tem 2026
- CVE-2026-5340539İzleyin
Apache Syncope: Remote Code Execution via Flowable BPMN Groovy ScriptTask
KritikCVSS 9,8İstismar yokEPSS %1apache · syncope20 Tem 2026
- CVE-2026-3477539İzleyin
Electron: nodeIntegrationInWorker not correctly scoped in shared renderer processes
KritikCVSS 9,8İstismar yokEPSS %0electronjs · electron3 Nis 2026
- CVE-2026-054236İzleyin
Remote Code Execution in ServiceNow AI Platform
KritikCVSS 9,2Kavram kanıtıEPSS %1servicenow · servicenow ai platform25 Şub 2026
- CVE-2025-408336İzleyin
Process isolation bypass using "javascript:" URI links in cross-origin frames
KritikCVSS 9,1İstismar yokEPSS %0mozilla · firefox29 Nis 2025
- CVE-2025-5773835İzleyin
Apache Syncope: Remote Code Execution by delegated administrators
YüksekCVSS 7,2İstismar yokEPSS %23apache · syncope20 Eki 2025
- CVE-2025-547635İzleyin
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0sony · xav-ax8500 firmware20 Haz 2025
- CVE-2026-4096835İzleyin
Spring gRPC SecurityContext leaks across requests on authorization failure
YüksekCVSS 8,8İstismar yokEPSS %0vmware · spring grpc28 Nis 2026
- CVE-2024-2028535İzleyin
Cisco NX-OS Software Python Parser Escape Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0cisco · nx-os28 Ağu 2024
- CVE-2025-3420134İzleyin
Vasion Print (formerly PrinterLogic) Lack of Network Segmentation Between Docker Instances
YüksekCVSS 8,5İstismar yokEPSS %0vasion · virtual appliance application19 Eyl 2025
- CVE-2024-013633İzleyin
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code
YüksekCVSS 8,4İstismar yokEPSS %1nvidia · nvidia container toolkit27 Oca 2025
- CVE-2026-6563533İzleyin
Boruta dynamic client registration allows creation of over-privileged OAuth clients
YüksekCVSS 8,3İstismar yokEPSS %1malach-it · boruta30 Tem 2026
- CVE-2026-9569933İzleyin
MrSteam iSteamX Improper Isolation or Compartmentalization
YüksekCVSS 8,4İstismar yokEPSS %0mrsteam · isteamx application5 gün önce
- CVE-2023-130532İzleyin
Rapid7 InsightCloudSec box object access
YüksekCVSS 8,1İstismar yokEPSS %1rapid7 · insightappsec21 Mar 2023
- CVE-2025-1280532İzleyin
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
YüksekCVSS 8,1İstismar yokEPSS %0redhat · openshift ai26 Mar 2026
- CVE-2024-2368332İzleyin
Artemis Java Test Sandbox InvocationTargetException Subclass Escape
YüksekCVSS 8,2İstismar yokEPSS %0ls1intum · artemis java test sandbox19 Oca 2024
- CVE-2024-3528131İzleyin
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.
YüksekCVSS 7,8İstismar yokEPSS %0fortinet · forticlient13 May 2025
- CVE-2024-013530İzleyin
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification o
YüksekCVSS 7,6İstismar yokEPSS %1nvidia · nvidia container toolkit27 Oca 2025
- CVE-2026-5713530İzleyin
PraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clients
YüksekCVSS 7,6İstismar yokEPSS %0mervinpraison · praisonai15 Eyl 2026
- CVE-2024-4752030İzleyin
A user with advanced report application access rights can perform actions for which they are not authorized
YüksekCVSS 7,6İstismar yokEPSS %0arista · ng firewall10 Oca 2025