Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-501

Trust Boundary Violation

The product mixes trusted and untrusted data in the same data structure or structured message.

31
Assigned CVEs
280th
Commonality Rank
7.7
Avg CVSS
3.2%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-501 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-61884HIGH
Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vu
Oct 12, 20257.598YESYES
CVE-2026-35051CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth midd
Apr 30, 202610.041NONO
CVE-2026-48746CRITICAL
vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette's trust on those web servers en
Jun 22, 20269.139NONO
CVE-2026-25725CRITICAL
Claude Code is an agentic coding tool. Prior to version 2.1.2, Claude Code's bubblewrap sandboxing mechanism failed to properly protect the .claude/settings.json configuration file
Feb 6, 202610.034NONO
CVE-2025-64496HIGH
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and prior contain a code injection vulnerability in the Direct C
Nov 8, 20258.034NONO
CVE-2026-27893HIGH
vLLM is an inference and serving engine for large language models (LLMs). Starting in version 0.10.1 and prior to version 0.18.0, two model implementation files hardcode `trust_rem
Mar 27, 20268.833NONO
CVE-2026-33828HIGH
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
Jun 9, 20267.831NONO
CVE-2026-4687HIGH
Sandbox escape due to incorrect boundary conditions in the Telemetry component. This vulnerability was fixed in Firefox 149, Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird 149,
Mar 24, 20268.630NONO
CVE-2020-4077CRITICAL
In Electron before versions 7.2.4, 8.2.4, and 9.0.0-beta21, there is a context isolation bypass. Code running in the main world context in the renderer can reach into the isolated
Jul 7, 20209.930NONO
CVE-2026-49458MEDIUM
DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathML, and SVG. Prior to 3.4.6, DOMPurify.sanitize(node, { IN_PLACE: true }) accepted same-origin foreign-realm DO
Jul 14, 20266.128NONO
View all 31 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
23%
16%
6.0-6.9
29%
26%
7.0-7.9
16%
11%
8.0-8.9
23%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
3.2% of CVEs· 97th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.2% of CVEs· 93rd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products