CWE-653

CWE-653 · 4 records · 3 with a public proof-of-concept

Records the NVD classes under CWE-653, highest CVSS first.

  1. CRITICAL 9.6CVE-2026-95699

    Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked expos…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-82964public PoC

    Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it …

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 6.3CVE-2026-101078public PoC

    A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or comp…

    AI risk analysis on Exploit-DB.ai →

  4. MEDIUM 5.7CVE-2026-97029public PoC

    Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause …

    AI risk analysis on Exploit-DB.ai →