CWE-653
CWE-653 · 4 records · 3 with a public proof-of-concept
Records the NVD classes under CWE-653, highest CVSS first.
- CRITICAL 9.6CVE-2026-95699
Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT topics, which can expose other users' device data and allow the attacker to start and stop other connected users' devices. This risked expos…
- HIGH 8.8CVE-2026-82964public PoC
Improper preservation of permissions in the Avast sandbox minifilter driver (aswSnx.sys) on Windows allows a local, low-privileged attacker executing inside the sandbox to escape file isolation and escalate to SYSTEM. When the sandbox virtualizes a file it …
- MEDIUM 6.3CVE-2026-101078public PoC
A vulnerability has been found in deepseek-ai deepseek-harness up to 0.1.7-rc.2. Affected is an unknown function of the file packages/sandbox/sandbox-local/src/profiles.ts of the component Landlock Backend. Such manipulation leads to improper isolation or comp…
- MEDIUM 5.7CVE-2026-97029public PoC
Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls from reaching processes outside the sandbox that share the same process group. A malicious or compromised Flatpak app can use this to cause …