CWE-657 · 18 записей
Violation of Secure Design Principles
CVE этого класса
18 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
39Наблюдать | CVE-2026-39888Эксплойта нет | PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)praison · praisonai · CWE-657 | Критическая9,9 | — | 0,6 % | 8 апр. 2026 г. |
33Наблюдать | CVE-2023-29320Эксплойта нет | ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flawadobe · acrobat dc · CWE-657 | Высокая7,8 | — | 5,4 % | 10 авг. 2023 г. |
32Наблюдать | GHSA-8xw8-mmqv-frqqЭксплойта нет | fake-static allows converting any reference into a `'static` referencecrates.io · fake-static · CWE-657 | Высокая8,0 | — | — | 25 авг. 2021 г. |
31Наблюдать | CVE-2019-0061Эксплойта нет | Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalationjuniper · junos · CWE-657 | Высокая7,8 | — | 0,4 % | 9 окт. 2019 г. |
30Наблюдать | CVE-2026-48399Эксплойта нет | Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)adobe · campaign · CWE-657 | Высокая7,5 | — | 0,9 % | 3 авг. 2026 г. |
30Наблюдать | CVE-2023-52714Эксплойта нет | Vulnerability of defects introduced in the design process in the hwnff module.huawei · emui · CWE-657 | Высокая7,5 | — | 0,3 % | 7 апр. 2024 г. |
30Наблюдать | CVE-2024-57957Эксплойта нет | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affechuawei · harmonyos · CWE-657 | Высокая7,5 | — | 0,3 % | 6 февр. 2025 г. |
26Наблюдать | CVE-2022-28244Эксплойта нет | Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalationadobe · acrobat dc · CWE-657 | Средняя6,3 | — | 3,6 % | 11 мая 2022 г. |
22Наблюдать | CVE-2019-5478Эксплойта нет | A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.amd · zu11eg firmware · CWE-657 | Средняя5,5 | — | 0,2 % | 3 сент. 2019 г. |
22Наблюдать | GHSA-qm5v-pj64-852jЭксплойта нет | Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"Packagist · passbolt/passbolt_api · CWE-657 | Средняя5,5 | — | — | 20 мая 2024 г. |
21Наблюдать | CVE-2017-6032Эксплойта нет | A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.schneider-electric · modbus firmware · CWE-657 | Средняя5,3 | — | 1,7 % | 29 июн. 2017 г. |
21Наблюдать | CVE-2021-36061Эксплойта нет | Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordingsadobe · connect · CWE-657 | Средняя5,4 | — | 1,6 % | 1 сент. 2021 г. |
21Наблюдать | CVE-2022-30683Эксплойта нет | AEM Violation of Secure Design Principles Security feature bypassadobe · experience manager · CWE-657 | Средняя5,3 | — | 0,7 % | 16 сент. 2022 г. |
21Наблюдать | CVE-2020-8133Эксплойта нет | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.nextcloud · nextcloud server · CWE-657 | Средняя5,3 | — | 0,7 % | 9 нояб. 2020 г. |
19Наблюдать | CVE-2019-15611Эксплойта нет | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when searnextcloud · nextcloud · CWE-657 | Средняя4,9 | — | 1,1 % | 4 февр. 2020 г. |
17Наблюдать | CVE-2021-28583Эксплойта нет | Magento Commerce insecure storage of sensitive documentationmagento · magento · CWE-657 | Средняя4,2 | — | 1,9 % | 28 июн. 2021 г. |
16Наблюдать | CVE-2025-54255Эксплойта нет | Acrobat Reader | Violation of Secure Design Principles (CWE-657)adobe · acrobat · CWE-657 | Средняя4,0 | — | 0,3 % | 9 сент. 2025 г. |
14Наблюдать | CVE-2021-44714Эксплойта нет | Adobe Acrobat Reader Missing Custom Protocols in Warning Message Promptsadobe · acrobat dc · CWE-657 | Низкая3,3 | — | 2,6 % | 14 янв. 2022 г. |
- CVE-2026-3988839Наблюдать
PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
КритическаяCVSS 9,9Эксплойта нетEPSS 1 %praison · praisonai8 апр. 2026 г.
- CVE-2023-2932033Наблюдать
ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw
ВысокаяCVSS 7,8Эксплойта нетEPSS 5 %adobe · acrobat dc10 авг. 2023 г.
- GHSA-8xw8-mmqv-frqq32Наблюдать
fake-static allows converting any reference into a `'static` reference
ВысокаяCVSS 8,0Эксплойта нетcrates.io · fake-static25 авг. 2021 г.
- CVE-2019-006131Наблюдать
Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %juniper · junos9 окт. 2019 г.
- CVE-2026-4839930Наблюдать
Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %adobe · campaign3 авг. 2026 г.
- CVE-2023-5271430Наблюдать
Vulnerability of defects introduced in the design process in the hwnff module.
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · emui7 апр. 2024 г.
- CVE-2024-5795730Наблюдать
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affec
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %huawei · harmonyos6 февр. 2025 г.
- CVE-2022-2824426Наблюдать
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
СредняяCVSS 6,3Эксплойта нетEPSS 4 %adobe · acrobat dc11 мая 2022 г.
- CVE-2019-547822Наблюдать
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %amd · zu11eg firmware3 сент. 2019 г.
- GHSA-qm5v-pj64-852j22Наблюдать
Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"
СредняяCVSS 5,5Эксплойта нетPackagist · passbolt/passbolt_api20 мая 2024 г.
- CVE-2017-603221Наблюдать
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.
СредняяCVSS 5,3Эксплойта нетEPSS 2 %schneider-electric · modbus firmware29 июн. 2017 г.
- CVE-2021-3606121Наблюдать
Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings
СредняяCVSS 5,4Эксплойта нетEPSS 2 %adobe · connect1 сент. 2021 г.
- CVE-2022-3068321Наблюдать
AEM Violation of Secure Design Principles Security feature bypass
СредняяCVSS 5,3Эксплойта нетEPSS 1 %adobe · experience manager16 сент. 2022 г.
- CVE-2020-813321Наблюдать
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %nextcloud · nextcloud server9 нояб. 2020 г.
- CVE-2019-1561119Наблюдать
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when sear
СредняяCVSS 4,9Эксплойта нетEPSS 1 %nextcloud · nextcloud4 февр. 2020 г.
- CVE-2021-2858317Наблюдать
Magento Commerce insecure storage of sensitive documentation
СредняяCVSS 4,2Эксплойта нетEPSS 2 %magento · magento28 июн. 2021 г.
- CVE-2025-5425516Наблюдать
Acrobat Reader | Violation of Secure Design Principles (CWE-657)
СредняяCVSS 4,0Эксплойта нетEPSS 0 %adobe · acrobat9 сент. 2025 г.
- CVE-2021-4471414Наблюдать
Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts
НизкаяCVSS 3,3Эксплойта нетEPSS 3 %adobe · acrobat dc14 янв. 2022 г.