CWE-501
15 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-501page 1 of 1
- CVE-2019-0035MEDIUMCVSS 6.82019-04-10
When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Ope…
- CVE-2020-15096MEDIUMCVSS 6.8EG 6.82020-07-07
In Electron before versions 6.1.1, 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass, meaning that code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged…
- CVE-2020-4076HIGHCVSS 7.8EG 7.82020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using…
- CVE-2020-4077HIGHCVSS 7.7EG 7.72020-07-07
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated Electron context and perform privileged actions. Apps using…
- CVE-2022-1799MEDIUMCVSS 5.7EG 9.82022-07-29
Incorrect signature trust exists within Google Play services SDK play-services-basement. A debug version of Google Play services is trusted by the SDK for devices that are non-GMS. We recommend upgrading the SDK past the 2022-05-03 release.
- CVE-2022-20826MEDIUMCVSS 6.4EG 6.82022-11-15
A vulnerability in the secure boot implementation of Cisco Secure Firewalls 3100 Series that are running Cisco Adaptive Security Appliance (ASA) Software or Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated attac…
- CVE-2023-0627MEDIUMCVSS 6.7EG 7.82023-09-25
Docker Desktop 4.11.x allows --no-windows-containers flag bypass via IPC response spoofing which may lead to Local Privilege Escalation (LPE).This issue affects Docker Desktop: 4.11.X.
- CVE-2023-0629HIGHCVSS 7.1EG 7.12023-03-13
Docker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation (ECI) restrictions by setting the Docker host to docker.raw.sock, or npipe:////.pipe/docker_engine_linux on Windows, via the -H (--host) CLI fl…
- CVE-2023-28597HIGHCVSS 8.3EG 7.52023-03-27
Zoom clients prior to 5.13.5 contain an improper trust boundary implementation vulnerability. If a victim saves a local recording to an SMB location and later opens it using a link from Zoom’s web portal, an attacker positioned on an adj…
- CVE-2023-49788HIGHCVSS 7.2EG 7.22023-12-08
Collabora Online is a collaborative online office suite based on LibreOffice technology. Unlike a standalone dedicated Collabora Online server, the Built-in CODE Server (richdocumentscode) is run without chroot sandboxing. Vulnerable versi…
- CVE-2024-1725MEDIUMCVSS 6.5EG 6.52024-03-07
A flaw was found in the kubevirt-csi component of OpenShift Virtualization's Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker node's volume by creating a custom Persistent V…
- CVE-2024-20265MEDIUMCVSS 5.9EG 5.92024-03-27
A vulnerability in the boot process of Cisco Access Point (AP) Software could allow an unauthenticated, physical attacker to bypass the Cisco Secure Boot functionality and load a software image that has been tampered with on an affected de…
- CVE-2024-23682HIGHCVSS 8.2EG 8.22024-01-19
Artemis Java Test Sandbox versions before 1.8.0 are vulnerable to a sandbox escape when an attacker includes class files in a package that Ares trusts. An attacker can abuse this issue to execute arbitrary Java when a victim executes the s…
- CVE-2024-3661HIGHCVSS 7.6EG 8.82024-05-06
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on t…
- CVE-2024-49050HIGHCVSS 8.8EG 8.82024-11-12
Visual Studio Code Python Extension Remote Code Execution Vulnerability
Map vulnerabilities like CWE-501 to your infrastructure
EchelonGraph correlates every CVE — across CWE-501 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →