CWE-653: CWE-653

25
Total CVEs
3
Critical
8
High
6.8
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
1
2025
22
2024
2

Top Affected Vendors

1 Sammycage 4
2 Nvidia 3
3 Fortinet 2
4 Microsoft 1
5 Eclipse 1
6 Sony 1
7 Mozilla 1
8 Juniper 1
9 Arista 1
10 Ls1intum 1

All CWE-653 CVEs (25)

CVE-2025-1974
EPSS 90.7% 9.8

CVE-2025-1974 is a critical vulnerability in Kubernetes' ingress-nginx controller that allows unauthenticated attackers on the pod network to execute ...

Mar 25, 2025
CVE-2024-33768
9.8

CVE-2024-33768 is a critical vulnerability in lunasvg v2.3.9 that allows attackers to trigger a segmentation violation via the composition_solid_sourc...

May 1, 2024
CVE-2025-4083
9.1

A process isolation vulnerability in Thunderbird and Firefox allows javascript: URIs to execute in the top-level document's process instead of the int...

Apr 29, 2025
CVE-2025-5476
8.8

This vulnerability allows attackers within Bluetooth range to bypass authentication on Sony XAV-AX8500 car multimedia systems. The flaw exists in Blue...

Jun 21, 2025
CVE-2024-23683
8.2

CVE-2024-23683 is a sandbox escape vulnerability in Artemis Java Test Sandbox (part of the Ares framework) that allows attackers to execute arbitrary ...

Jan 19, 2024
CVE-2025-20109
7.8

This vulnerability in Intel processors allows an authenticated user with local access to potentially escalate privileges by exploiting improper isolat...

Aug 12, 2025
CVE-2024-0135
7.6

NVIDIA Container Toolkit has an improper isolation vulnerability where malicious container images can modify host binaries. This affects systems using...

Jan 28, 2025
CVE-2024-0136
7.6

NVIDIA Container Toolkit has an improper isolation vulnerability where specially crafted container images could allow untrusted code to access host de...

Jan 28, 2025
CVE-2024-47520
7.6

This vulnerability allows users with advanced report application access rights to perform unauthorized actions beyond their intended permissions. It a...

Jan 10, 2025
CVE-2025-53710
7.5

This CVE describes a container escape vulnerability in Foundry Container Service where misconfigured deployments allow pods within the same namespace ...

Dec 18, 2025
CVE-2025-41688
7.2

This vulnerability allows a high-privileged remote attacker to execute arbitrary operating system commands by escaping the LUA sandbox implementation....

Jul 31, 2025
CVE-2025-24986
6.5

This vulnerability in Azure PromptFlow allows unauthorized attackers to execute arbitrary code remotely due to improper isolation between components. ...

Mar 11, 2025
CVE-2024-55456
6.5

CVE-2024-55456 is a segmentation violation vulnerability in lunasvg's gray_find_cell component that can cause denial of service or potentially allow a...

Feb 3, 2025
CVE-2024-57723
6.5

CVE-2024-57723 is a segmentation violation vulnerability in lunasvg's composition_source_over component that can cause denial of service or potentiall...

Jan 23, 2025
CVE-2024-57721
6.5

Lunasvg v3.0.0 contains a segmentation violation vulnerability in the plutovg_path_add_path component that can cause denial of service or potentially ...

Jan 23, 2025
CVE-2025-12695
5.9

This vulnerability in DSPy's PythonInterpreter class allows attackers to bypass sandbox restrictions and read arbitrary files when users build AI agen...

Nov 4, 2025
CVE-2026-25905
5.8

This vulnerability in the archived 'mcp-run-python' project allows Python code executed via Pyodide to modify the JavaScript environment without isola...

Feb 9, 2026
CVE-2024-0137
5.5

NVIDIA Container Toolkit has an improper isolation vulnerability where specially crafted container images could allow untrusted code to run in the hos...

Jan 28, 2025
CVE-2025-46215
5.3

An improper isolation vulnerability in Fortinet FortiSandbox allows unauthenticated attackers to bypass sandbox scanning by submitting specially craft...

Nov 18, 2025
CVE-2025-6705
5.3

A vulnerability in Eclipse Open VSX Registry's automated publishing system allowed unauthorized uploads of extensions due to insufficient isolation of...

Jun 27, 2025
CVE-2025-21590
KEV 4.4

A local privilege escalation vulnerability in Juniper Junos OS kernel allows attackers with shell access to inject arbitrary code and compromise devic...

Mar 12, 2025
CVE-2025-27027
4.1

This vulnerability allows users with vpuser credentials to bypass restricted shell (rbash) limitations and gain a full-featured Linux shell on affecte...

Jul 9, 2025
CVE-2024-35281
2.5

This vulnerability allows authenticated attackers to inject code via Electron environment variables in Fortinet desktop applications. It affects Forti...

May 13, 2025
CVE-2025-41116
N/A

This vulnerability in the Grafana Databricks Datasource Plugin allows unauthorized data access when OAuth passthrough is enabled and multiple users sh...

Nov 11, 2025
CVE-2025-3717
N/A

This vulnerability in the Grafana Snowflake Datasource Plugin allows user identifier confusion when OAuth passthrough is enabled and multiple users ac...

Nov 11, 2025

About CWE-653 (CWE-653)

Our database tracks 25 CVEs classified as CWE-653, with 3 rated critical and 8 rated high severity. The average CVSS score for CWE-653 vulnerabilities is 6.8.

External reference: View CWE-653 on MITRE CWE →

Monitor CWE-653 Vulnerabilities

Get alerted when new CWE-653 CVEs affect your infrastructure.

Start Monitoring Free