Auto-created placeholder
Volume of CVEs assigned to CWE-265 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-1889CRITICAL A security feature bypass issue in WhatsApp Desktop versions prior to v0.3.4932 could have allowed for sandbox escape in Electron and escalation of privilege if combined with a rem | Sep 3, 2020 | 10.0 | 32 | NO | NO |
CVE-2026-14784MEDIUM A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipula | Jul 6, 2026 | 6.3 | 30 | NO | NO |
CVE-2026-9368HIGH A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Enviro | May 24, 2026 | 7.3 | 30 | NO | NO |
CVE-2023-26122CRITICAL All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation.
Explo | Apr 11, 2023 | 10.0 | 30 | NO | NO |
CVE-2024-2007HIGH A vulnerability was found in OpenBMB XAgent 1.0.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Privileged Mode. Th | Mar 21, 2024 | 8.8 | 28 | NO | NO |
CVE-2023-5223CRITICAL A vulnerability, which was classified as critical, has been found in HimitZH HOJ up to 4.6-9a65e3f. This issue affects some unknown processing of the component Topic Handler. The m | Sep 27, 2023 | 9.9 | 28 | NO | NO |
CVE-2025-5321CRITICAL A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of th | May 29, 2025 | 9.9 | 27 | NO | NO |
CVE-2026-6224HIGH A security flaw has been discovered in nocobase plugin-workflow-javascript up to 2.0.23. This issue affects the function createSafeConsole of the file packages/plugins/@nocobase/pl | Apr 13, 2026 | 7.3 | 25 | NO | NO |
CVE-2026-6117MEDIUM A vulnerability was found in AstrBotDevs AstrBot up to 4.22.1. This issue affects the function install_plugin_upload of the file astrbot/dashboard/routes/plugin.py of the component | Apr 12, 2026 | 6.3 | 23 | NO | NO |
CVE-2026-6878MEDIUM A vulnerability was identified in ByteDance verl up to 0.7.0. Affected is the function math_equal of the file prime_math/grader.py. The manipulation leads to sandbox issue. It is p | Apr 23, 2026 | 5.6 | 20 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.