VulnSea

CWE-501

CVEs classified under CWE-501, newest first.

19 CVEsRSS

CVE-2026-92035Critical· 9.6⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Graphics component

Sandbox escape due to incorrect boundary conditions in the Graphics component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92048Critical· 9.0⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

MidnightMozilla · FirefoxEPSS 0.15%via NVD
CVE-2026-92071Low· 3.4
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

SunlitMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-92064High· 8.8⚖ disputed
1w ago

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component

Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156, and Thunderbird 153.3.

TwilightMozilla · FirefoxEPSS 0.14%via NVD
CVE-2026-54248Medium· 6.5
1w ago

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks

Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed artifact-provided …

Sunlitkimdre · doco-cdEPSS 0.23%via NVD
CVE-2026-80946Medium· 5.5
1w ago

kernel: fuse: copy request headers via a stack buffer for io-uring (CVE-2026-80946)

A flaw was found in the Linux kernel's FUSE (Filesystem in Userspace) component. The `io-uring` transport attempts to copy request headers directly to or from user space without proper memory validation. A local attacker could exploit this…

SunlitRed Hat · Red Hat OpenShift Container Platform 4EPSS 0.17%via CSAF
CVE-2026-82209High· 8.2PoC⚖ disputed
2w ago

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a `Set-Cookie` header where the `Domain` attribute explicitly matches an origin host that is itself a public suffix (e.g., `Do…

Midnighthaxx · curlEPSS 0.54%via NVD
CVE-2026-74960High· 8.1⚖ disputed
1mo ago

Site isolation issue in the WebExtensions component

Site isolation issue in the WebExtensions component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, and Thunderbird 153.1.

TwilightRed Hat · Red Hat Enterprise Linux AppStream (v. 10)EPSS 0.16%via NVD
CVE-2026-44091Critical· 9.1
1mo ago

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss.

MidnightEPSS 0.36%via NVD
CVE-2026-48746Critical· 9.1PoC
3mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers enables an authentication bypass of the OpenAI API Authenti…

Abyssalvllm · vllmEPSS 1.2%via NVD
CVE-2026-49458Medium· 6.1
3mo ago

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks

Sunlitdompurify · dompurifyEPSS 0.40%via GHSA
GHSA-76mc-f452-cxcmMedium· 6.1
3mo ago

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

DOMPurify: Hook mutation of `data.allowedTags` / `data.allowedAttributes` permanently pollutes `DEFAULT_ALLOWED_TAGS` / `DEFAULT_ALLOWED_ATTR`

Sunlitdompurify · dompurifyvia GHSA
CVE-2026-27140High· 8.8
5mo ago

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

SWIG file names containing 'cgo' and well-crafted payloads could lead to code smuggling and arbitrary code execution at build time due to trust layer bypass.

Twilightgolang · goEPSS 0.66%via NVD
CVE-2026-24153Medium· 5.2
5mo ago

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled

NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.

Sunlitnvidia · jetson_linuxEPSS 0.12%via NVD
CVE-2026-27893High· 8.8
5mo ago

vLLM is an inference and serving engine for large language models (LLMs)

vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_remote_code=True` when loading sub-components, bypassing the…

Twilightvllm · vllmEPSS 1.3%via NVD
CVE-2025-61884High· 7.5CISA KEVPoC
11mo ago

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI)

Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network …

Abyssaloracle · configuratorEPSS 96%via NVD
CVE-2025-48938Critical· 9.8
1y ago

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier

go-gh is a collection of Go modules to make authoring GitHub CLI extensions easier. A security vulnerability has been identified in versions prior to 2.12.1 where an attacker-controlled GitHub Enterprise Server could result in executing …

Midnightcli · go-ghEPSS 0.53%via NVD
CVE-2025-1118Medium· 4.4
1y ago

A flaw was found in grub2

A flaw was found in grub2. Grub's dump command is not blocked when grub is in lockdown mode, which allows the user to read any memory information, and an attacker may leverage this in order to extract signatures, salts, and other sensiti…

SunlitEPSS 0.32%via NVD
CVE-2024-23682High· 8.2
2y ago

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts

Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the…

Twilightls1intum · artemis_java_test_sandboxEPSS 0.35%via NVD
CWE-501 vulnerabilities (CVEs) · VulnSea