CWE-653
Improper Isolation or Compartmentalization
The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.
71 vulnerabilities with CWE-653
CVE-2026-4692
CRITICAL
Sandbox escape in the Responsive Design Mode component
CVSS 10.0
CVE-2026-0542
CRITICAL
ServiceNow AI Platform - Unauthenticated Remote Code Execution in Sandbox
CVE-2026-25905
MEDIUM
mcp-run-python - Improper Isolation via Pyodide API Access
CVSS 5.8
CVE-2025-12805
HIGH
Llama-stack-k8s-operator: llama stack service exposed across namespaces due to missing networkpolicy
CVSS 8.1
CVE-2025-53710
HIGH
Foundry Container Service - Privilege Escalation
CVSS 7.5
CVE-2025-46215
MEDIUM
Fortinet FortiSandbox <5.0.1 - Info Disclosure
CVSS 5.3
CVE-2025-41116
LOW
Grafana Databricks Datasource Plugin <1.12.0 - Info Disclosure
CVE-2025-3717
LOW
Grafana Snowflake Datasource Plugin <1.14.1 - Info Disclosure
CVE-2025-12695
MEDIUM
DSPy - Arbitrary File Read via PythonInterpreter Sandbox Escape
CVSS 5.9
CVE-2025-57738
HIGH
Apache Syncope 2.1.0-3.0.13 - Authenticated Remote Code Execution via Groovy Class Injection
CVSS 7.2
CVE-2025-34201
HIGH
Vasion Print Virtual Appliance Host - Lateral Movement
CVSS 7.8
CVE-2025-20109
HIGH
Intel(R) Processors - Privilege Escalation
CVSS 7.8
CVE-2025-41688
HIGH
MB connect line mbNET HW1 < 5.1.11 and mbNET/mbNET.rokey < 7.3.0 - Remote Code Execution via LUA Sandbox Escape
CVSS 7.2
CVE-2025-27027
MEDIUM
Radiflow iSAP Smart Collector 1.20-3.02-1 - Authenticated Restricted Shell Bypass via rbash
CVSS 4.1
CVE-2025-6705
MEDIUM
Eclipse Open VSX Registry - Privilege Escalation
CVSS 5.3
CVE-2025-5476
HIGH
Sony XAV-AX8500 Firmware >=2.00.01 <3.02.00 - Unauthenticated Authentication Bypass via ACL-U Links
CVSS 8.8
CVE-2025-4083
CRITICAL
Thunderbird <138 - Sandbox Escape
CVSS 9.1
CVE-2025-3086
HIGH
M-Files Server < 25.3.14549 - Unauthenticated Denial of Service via User Isolation Bypass
CVSS 7.1
CVE-2025-1974
CRITICAL
Kubernetes ingress-nginx - Pod Network Remote Code Execution
CVSS 9.8
CVE-2025-29781
MEDIUM
Bare Metal Operator < 0.8.1 and 0.9.0 - Unauthorized Secret Access via BMCEventSubscription
CVSS 6.5
CVE-2025-26393
MEDIUM
SolarWinds Service Desk - Privilege Escalation
CVSS 5.4
CVE-2025-21590
MEDIUM
KEV
Juniper Networks Junos OS <21.2R3-S9, <21.4R3-S10, <22.2R3-S - Priv...
CVSS 4.4
CVE-2025-24986
MEDIUM
Azure PromptFlow Core < 1.17.2 and PromptFlow Tools < 1.6.0 - Unauthenticated Remote Code Execution
CVSS 6.5
CVE-2024-35281
LOW
FortiClientMac <7.4.2 - Code Injection
CVSS 2.5
CVE-2024-55456
MEDIUM
lunasvg 3.0.1 - Segmentation Violation in gray_find_cell
CVSS 6.5
Details
Vulnerabilities
71