Sandbox escape in the Responsive Design Mode component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34,
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are vario
vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sa
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlemen
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements
Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefo
Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox
Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2
Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, Kamaji derives a TenantControlPlane dat
A flaw was found in Red Hat OpenShift AI (RHOAI) llama-stack-operator. This vulnerability allows unauthorized access to
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso
Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to version
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potent
The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any
An attacker could cooperatively pass data from one secure GPU process to another secure GPU process through shared secur
A flaw was found in Keycloak. The SingleUseObjectProvider, a global key-value store, lacks proper type and namespace iso
A new API endpoint introduced in pretix 2025 that is supposed to return all check-in events of a specific event in fact
When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC wor
ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This
A user with API access and "manage users" permission in any venueless world is able to trigger deletion of user account
Improper Isolation or Compartmentalization vulnerability in malach-it boruta (Elixir.Boruta.Openid module) allows attack
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25
A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi
Frequently Asked Questions
What is CWE-653?
CWE-653 (CWE-653) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-653?
There are 32 CVE records associated with CWE-653 in our database. Of these, 13 are critical severity, 6 are high severity, and 7 are medium severity.
How can I protect against CWE-653 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-653 using AI-powered security agents.
Detect CWE-653 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-653 vulnerabilities across your infrastructure.
Get Started