CWE-653
52 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-653page 1 of 2
- CVE-2023-1305HIGHCVSS 8.1EG 8.12023-03-21
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, …
- CVE-2023-1636MEDIUMCVSS 6.0EG 6.02023-09-24
A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, USER, and NET namespace with the host sys…
- CVE-2023-29580MEDIUMCVSS 5.5EG 5.52023-04-12
yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.
- CVE-2024-0135HIGHCVSS 7.6EG 7.62025-01-28
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability may lead to code execution, denial of s…
- CVE-2024-0136HIGHCVSS 7.6EG 7.62025-01-28
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDI…
- CVE-2024-0137MEDIUMCVSS 5.5EG 5.52025-01-28
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability is present only when the NVIDIA Cont…
- CVE-2024-20285MEDIUMCVSS 5.3EG 5.32024-08-28
A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlying operating system of the device. T…
- CVE-2024-23682HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the s…
- CVE-2024-23683HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions less than 1.7.6 are vulnerable to a sandbox escape when an attacker crafts a special subclass of InvocationTargetException. An attacker can abuse this issue to execute arbitrary Java when a victim execute…
- CVE-2024-30388MEDIUMCVSS 6.5EG 6.52024-04-12
An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).…
- CVE-2024-33768CRITICALCVSS 9.8EG 9.82024-05-01
lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.
- CVE-2024-35281LOWCVSS 2.5EG 2.52025-05-13
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authentica…
- CVE-2024-35425MEDIUMCVSS 5.5EG 5.52024-11-08
vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.
- CVE-2024-43803MEDIUMCVSS 4.9EG 4.92024-09-03
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. The `BareMetalHost` (BMH) CRD allows the `userData`, `metaData`, and `networkData` for the provisioned host to be specified as links to Kube…
- CVE-2024-47520HIGHCVSS 7.6EG 7.62025-01-10
A user with advanced report application access rights can perform actions for which they are not authorized
- CVE-2024-49373MEDIUMCVSS 4.1EG 4.12024-10-22
No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. Version 1.2.1 fixes the problem.
- CVE-2024-53855LOWCVSS 1.9EG 1.92024-11-27
Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions fo…
- CVE-2024-55456MEDIUMCVSS 6.5EG 6.52025-02-03
lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell
- CVE-2024-57720MEDIUMCVSS 6.5EG 6.52025-01-23
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.
- CVE-2024-57721MEDIUMCVSS 6.5EG 6.52025-01-23
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.
- CVE-2024-57723MEDIUMCVSS 6.5EG 6.52025-01-23
lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.
- CVE-2024-5801MEDIUMCVSS 5.3EG 0.02024-08-12
Enabled IP Forwarding feature in B&R Automation Runtime versions before 6.0.2 may allow remote attack-ers to compromise network security by routing IP-based packets through the host, potentially by-passing firewall, router, or NAC filterin…
- CVE-2024-6323HIGHCVSS 7.5EG 7.52024-06-27
Improper authorization in global search in GitLab EE affecting all versions from 16.11 prior to 16.11.5 and 17.0 prior to 17.0.3 and 17.1 prior to 17.1.1 allows an attacker leak content of a private repository in a public project.
- CVE-2024-8118MEDIUMCVSS 5.1EG 0.02024-09-26
In Grafana, the wrong permission is applied to the alert rule write API endpoint, allowing users with permission to write external alert instances to also write alert rules.
- CVE-2025-12695MEDIUMCVSS 5.9EG 5.92025-11-04
The overly permissive sandbox configuration in DSPy allows attackers to steal sensitive files in cases when users build an AI agent which consumes user input and uses the “PythonInterpreter” class.
- CVE-2025-1974CRITICALCVSS 9.8EG 9.82025-03-25
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to …
- CVE-2025-20109HIGHCVSS 7.8EG 7.82025-08-12
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2025-21590MEDIUMCVSS 4.4EG 9.0⚠ KEV2025-03-12
An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local attacker with access to the shell is ab…
- CVE-2025-24986MEDIUMCVSS 6.5EG 6.52025-03-11
Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.
- CVE-2025-26393MEDIUMCVSS 5.4EG 5.42025-03-17
SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.
- CVE-2025-27027MEDIUMCVSS 4.1EG 4.12025-07-09
A user with vpuser credentials that opens an SSH connection to the device, gets a restricted shell rbash that allows only a small list of allowed commands. This vulnerability enables the user to get a full-featured Linux shell, bypassing…
- CVE-2025-29781MEDIUMCVSS 6.5EG 6.52025-03-17
The Bare Metal Operator (BMO) implements a Kubernetes API for managing bare metal hosts in Metal3. Baremetal Operator enables users to load Secret from arbitrary namespaces upon deployment of the namespace scoped Custom Resource `BMCEventS…
- CVE-2025-3086HIGHCVSS 7.1EG 7.12025-04-04
Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service
- CVE-2025-34201HIGHCVSS 7.8EG 7.82025-09-19
Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) run many Docker containers on shared internal networks without firewalling or segmentation between instances. A compromise of any single …
- CVE-2025-3717LOWCVSS 2.1EG 0.02025-11-11
When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user i…
- CVE-2025-4083CRITICALCVSS 9.1EG 9.12025-04-29
A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended frame, potentially enabling a sandbox esc…
- CVE-2025-41116LOWCVSS 2.1EG 0.02025-11-11
When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple users are using the same datasource at the same time on a single Grafana instance, it could result in the wrong user …
- CVE-2025-41688HIGHCVSS 7.2EG 7.22025-07-31
A high privileged remote attacker can execute arbitrary OS commands using an undocumented method allowing to escape the implemented LUA sandbox.
- CVE-2025-46215MEDIUMCVSS 5.3EG 5.32025-11-18
An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated…
- CVE-2025-53710HIGHCVSS 7.5EG 7.52025-12-18
Due to a product misconfiguration in certain deployment types, it was possible from different pods in the same namespace to communicate with each other. This issue resulted in bypass of access control due to the presence of a vulnerable en…
- CVE-2025-5476HIGHCVSS 8.8EG 6.32025-06-21
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected Sony XAV-AX8500 devices. Authentication is not required to exploit …
- CVE-2025-57738HIGHCVSS 7.2EG 7.22025-10-20
Apache Syncope offers the ability to extend / customize the base behavior on every deployment by allowing to provide custom implementations of a few Java interfaces; such implementations can be provided either as Java or Groovy classes, wi…
- CVE-2025-6705MEDIUMCVSS 5.3EG 5.32025-06-27
A vulnerability in the Eclipse Open VSX Registry’s automated publishing system could have allowed unauthorized uploads of extensions. Specifically, the system’s build scripts were executed without proper isolation, potentially exposing…
- CVE-2026-25905MEDIUMCVSS 5.8EG 5.82026-02-09
The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any Python code to use the Pyodide APIs to modify the JS environment. This may result in an attacker hijacking the MCP serv…
- CVE-2026-34775MEDIUMCVSS 6.8EG 6.82026-04-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to versions 38.8.6, 39.8.4, 40.8.4, and 41.0.0, the nodeIntegrationInWorker webPreference was not correctly scoped in all configu…
- CVE-2026-40968MEDIUMCVSS 4.2EG 4.22026-04-28
When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subseque…
- CVE-2026-41174MEDIUMCVSS 6.4EG 6.42026-04-30
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetes…
- CVE-2026-42782HIGHCVSS 7.2EG 7.22026-05-25
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted code reaching a non-sandboxed execution …
- CVE-2026-4282HIGHCVSS 7.4EG 7.42026-04-02
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an unauthenticated attacker to forge authorization codes. Successful exploitation can…
- CVE-2026-4325MEDIUMCVSS 5.3EG 5.32026-04-02
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace isolation. This vulnerability allows an attacker to delete arbitrary single-use entries, which can enable the replay of co…
Map vulnerabilities like CWE-653 to your infrastructure
EchelonGraph correlates every CVE — across CWE-653 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →