Skip to content
Noroxi

CWE-657 · 18 records

Violation of Secure Design Principles

CVEs in this class

18 records

  • PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)

    CriticalCVSS 9.9No exploitEPSS 1%

    praison · praisonaiApr 8, 2026

  • ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw

    HighCVSS 7.8No exploitEPSS 5%

    adobe · acrobat dcAug 10, 2023

  • fake-static allows converting any reference into a `'static` reference

    HighCVSS 8.0No exploit

    crates.io · fake-staticAug 25, 2021

  • CVE-2019-0061
    31Monitor

    Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation

    HighCVSS 7.8No exploitEPSS 0%

    juniper · junosOct 9, 2019

  • Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)

    HighCVSS 7.5No exploitEPSS 1%

    adobe · campaignAug 3, 2026

  • Vulnerability of defects introduced in the design process in the hwnff module.

    HighCVSS 7.5No exploitEPSS 0%

    huawei · emuiApr 7, 2024

  • Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affec

    HighCVSS 7.5No exploitEPSS 0%

    huawei · harmonyosFeb 6, 2025

  • Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation

    MediumCVSS 6.3No exploitEPSS 4%

    adobe · acrobat dcMay 11, 2022

  • CVE-2019-5478
    22Monitor

    A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.

    MediumCVSS 5.5No exploitEPSS 0%

    amd · zu11eg firmwareSep 3, 2019

  • Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"

    MediumCVSS 5.5No exploit

    Packagist · passbolt/passbolt_apiMay 20, 2024

  • CVE-2017-6032
    21Monitor

    A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.

    MediumCVSS 5.3No exploitEPSS 2%

    schneider-electric · modbus firmwareJun 29, 2017

  • Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings

    MediumCVSS 5.4No exploitEPSS 2%

    adobe · connectSep 1, 2021

  • AEM Violation of Secure Design Principles Security feature bypass

    MediumCVSS 5.3No exploitEPSS 1%

    adobe · experience managerSep 16, 2022

  • CVE-2020-8133
    21Monitor

    A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

    MediumCVSS 5.3No exploitEPSS 1%

    nextcloud · nextcloud serverNov 9, 2020

  • Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when sear

    MediumCVSS 4.9No exploitEPSS 1%

    nextcloud · nextcloudFeb 4, 2020

  • Magento Commerce insecure storage of sensitive documentation

    MediumCVSS 4.2No exploitEPSS 2%

    magento · magentoJun 28, 2021

  • Acrobat Reader | Violation of Secure Design Principles (CWE-657)

    MediumCVSS 4.0No exploitEPSS 0%

    adobe · acrobatSep 9, 2025

  • Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts

    LowCVSS 3.3No exploitEPSS 3%

    adobe · acrobat dcJan 14, 2022

All vulnerability classes