CWE-657 · 18 records
Violation of Secure Design Principles
CVEs in this class
18 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2026-39888No exploit | PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)praison · praisonai · CWE-657 | Critical9.9 | — | 0.6% | Apr 8, 2026 |
33Monitor | CVE-2023-29320No exploit | ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flawadobe · acrobat dc · CWE-657 | High7.8 | — | 5.4% | Aug 10, 2023 |
32Monitor | GHSA-8xw8-mmqv-frqqNo exploit | fake-static allows converting any reference into a `'static` referencecrates.io · fake-static · CWE-657 | High8.0 | — | — | Aug 25, 2021 |
31Monitor | CVE-2019-0061No exploit | Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalationjuniper · junos · CWE-657 | High7.8 | — | 0.4% | Oct 9, 2019 |
30Monitor | CVE-2026-48399No exploit | Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)adobe · campaign · CWE-657 | High7.5 | — | 0.9% | Aug 3, 2026 |
30Monitor | CVE-2023-52714No exploit | Vulnerability of defects introduced in the design process in the hwnff module.huawei · emui · CWE-657 | High7.5 | — | 0.3% | Apr 7, 2024 |
30Monitor | CVE-2024-57957No exploit | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affechuawei · harmonyos · CWE-657 | High7.5 | — | 0.3% | Feb 6, 2025 |
26Monitor | CVE-2022-28244No exploit | Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalationadobe · acrobat dc · CWE-657 | Medium6.3 | — | 3.6% | May 11, 2022 |
22Monitor | CVE-2019-5478No exploit | A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.amd · zu11eg firmware · CWE-657 | Medium5.5 | — | 0.2% | Sep 3, 2019 |
22Monitor | GHSA-qm5v-pj64-852jNo exploit | Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"Packagist · passbolt/passbolt_api · CWE-657 | Medium5.5 | — | — | May 20, 2024 |
21Monitor | CVE-2017-6032No exploit | A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.schneider-electric · modbus firmware · CWE-657 | Medium5.3 | — | 1.7% | Jun 29, 2017 |
21Monitor | CVE-2021-36061No exploit | Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordingsadobe · connect · CWE-657 | Medium5.4 | — | 1.6% | Sep 1, 2021 |
21Monitor | CVE-2022-30683No exploit | AEM Violation of Secure Design Principles Security feature bypassadobe · experience manager · CWE-657 | Medium5.3 | — | 0.7% | Sep 16, 2022 |
21Monitor | CVE-2020-8133No exploit | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.nextcloud · nextcloud server · CWE-657 | Medium5.3 | — | 0.7% | Nov 9, 2020 |
19Monitor | CVE-2019-15611No exploit | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when searnextcloud · nextcloud · CWE-657 | Medium4.9 | — | 1.1% | Feb 4, 2020 |
17Monitor | CVE-2021-28583No exploit | Magento Commerce insecure storage of sensitive documentationmagento · magento · CWE-657 | Medium4.2 | — | 1.9% | Jun 28, 2021 |
16Monitor | CVE-2025-54255No exploit | Acrobat Reader | Violation of Secure Design Principles (CWE-657)adobe · acrobat · CWE-657 | Medium4.0 | — | 0.3% | Sep 9, 2025 |
14Monitor | CVE-2021-44714No exploit | Adobe Acrobat Reader Missing Custom Protocols in Warning Message Promptsadobe · acrobat dc · CWE-657 | Low3.3 | — | 2.6% | Jan 14, 2022 |
- CVE-2026-3988839Monitor
PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
CriticalCVSS 9.9No exploitEPSS 1%praison · praisonaiApr 8, 2026
- CVE-2023-2932033Monitor
ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw
HighCVSS 7.8No exploitEPSS 5%adobe · acrobat dcAug 10, 2023
- GHSA-8xw8-mmqv-frqq32Monitor
fake-static allows converting any reference into a `'static` reference
HighCVSS 8.0No exploitcrates.io · fake-staticAug 25, 2021
- CVE-2019-006131Monitor
Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
HighCVSS 7.8No exploitEPSS 0%juniper · junosOct 9, 2019
- CVE-2026-4839930Monitor
Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)
HighCVSS 7.5No exploitEPSS 1%adobe · campaignAug 3, 2026
- CVE-2023-5271430Monitor
Vulnerability of defects introduced in the design process in the hwnff module.
HighCVSS 7.5No exploitEPSS 0%huawei · emuiApr 7, 2024
- CVE-2024-5795730Monitor
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affec
HighCVSS 7.5No exploitEPSS 0%huawei · harmonyosFeb 6, 2025
- CVE-2022-2824426Monitor
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
MediumCVSS 6.3No exploitEPSS 4%adobe · acrobat dcMay 11, 2022
- CVE-2019-547822Monitor
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.
MediumCVSS 5.5No exploitEPSS 0%amd · zu11eg firmwareSep 3, 2019
- GHSA-qm5v-pj64-852j22Monitor
Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"
MediumCVSS 5.5No exploitPackagist · passbolt/passbolt_apiMay 20, 2024
- CVE-2017-603221Monitor
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.
MediumCVSS 5.3No exploitEPSS 2%schneider-electric · modbus firmwareJun 29, 2017
- CVE-2021-3606121Monitor
Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings
MediumCVSS 5.4No exploitEPSS 2%adobe · connectSep 1, 2021
- CVE-2022-3068321Monitor
AEM Violation of Secure Design Principles Security feature bypass
MediumCVSS 5.3No exploitEPSS 1%adobe · experience managerSep 16, 2022
- CVE-2020-813321Monitor
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
MediumCVSS 5.3No exploitEPSS 1%nextcloud · nextcloud serverNov 9, 2020
- CVE-2019-1561119Monitor
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when sear
MediumCVSS 4.9No exploitEPSS 1%nextcloud · nextcloudFeb 4, 2020
- CVE-2021-2858317Monitor
Magento Commerce insecure storage of sensitive documentation
MediumCVSS 4.2No exploitEPSS 2%magento · magentoJun 28, 2021
- CVE-2025-5425516Monitor
Acrobat Reader | Violation of Secure Design Principles (CWE-657)
MediumCVSS 4.0No exploitEPSS 0%adobe · acrobatSep 9, 2025
- CVE-2021-4471414Monitor
Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts
LowCVSS 3.3No exploitEPSS 3%adobe · acrobat dcJan 14, 2022