CWE-653

Total CVEs
26
Vulnerabilities
Avg CVSS v3
6.4
Medium
Latest CVE
2025
Most Recent

Severity Distribution

Critical 3
11.5%
High 6
23.1%
Medium 15
57.7%
Low 2
7.7%

External References

All CVEs (26)

Page 1 of 2
CVSS:9.8(Critical)

A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingr...

CVSS:9.8(Critical)

lunasvg v2.3.9 was discovered to contain a segmentation violation via the component composition_solid_source_over.

CVSS:9.1(Critical)

A process isolation vulnerability in Thunderbird stemmed from improper handling of javascript: URIs, which could allow content to execute in the top-level document's process instead of the intended fr...

CVSS:8.8(High)

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to escape the Python sandbox and gain unauthorized access to the underlyi...

CVSS:8.1(High)

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed a...

CVSS:7.6(High)

A user with advanced report application access rights can perform actions for which they are not authorized

CVSS:7.6(High)

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulne...

CVSS:7.6(High)

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to modification of a host binary. A successful exploit of this vulnerability ...

CVSS:6.5(Medium)

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

CVSS:6.5(Medium)

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component composition_source_over.

CVSS:6.5(Medium)

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_path_add_path.

CVSS:6.5(Medium)

lunasvg v3.0.0 was discovered to contain a segmentation violation via the component plutovg_blend.

CVSS:6.5(Medium)

lunasvg v3.0.1 was discovered to contain a segmentation violation via the component gray_find_cell

CVSS:6.5(Medium)

An Improper Isolation or Compartmentalization vulnerability in the Packet Forwarding Engine (pfe) of Juniper Networks Junos OS on QFX5000 Series and EX Series allows an unauthenticated, adjacent attac...

CVSS:5.5(Medium)

vmir e8117 was discovered to contain a segmentation violation via the function_prepare_parse function at /src/vmir_function.c.

CVSS:5.5(Medium)

NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code running in the host’s network namespace. This vulnerability...

CVSS:5.5(Medium)

yasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.

CVSS:5.4(Medium)

SolarWinds Service Desk is affected by a broken access control vulnerability. The issue allows authenticated users to escalate privileges, leading to unauthorized data manipulation.

CVSS:5.0(Medium)

A vulnerability was found in OpenStack Barbican containers. This vulnerability is only applicable to deployments that utilize an all-in-one configuration. Barbican containers share the same CGROUP, US...

CVSS:4.4(Medium)

An Improper Isolation or Compartmentalization vulnerability in the kernel of Juniper Networks Junos OS allows a local attacker with high privileges to compromise the integrity of the device. A local a...

CVSS:4.3(Medium)

No Fuss Computing Centurion ERP is open source enterprise resource planning (ERP) software. Prior to version 1.2.1, an authenticated user can view projects within organizations they are not apart of. ...

CVSS:2.5(Low)

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desk...

CVSS:1.9(Low)

Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is au...

Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service