CWE-657 · 18 kayıt
Violation of Secure Design Principles
Bu sınıftaki CVE’ler
18 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2026-39888İstismar yok | PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)praison · praisonai · CWE-657 | Kritik9,9 | — | %0,6 | 8 Nis 2026 |
33İzleyin | CVE-2023-29320İstismar yok | ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flawadobe · acrobat dc · CWE-657 | Yüksek7,8 | — | %5,4 | 10 Ağu 2023 |
32İzleyin | GHSA-8xw8-mmqv-frqqİstismar yok | fake-static allows converting any reference into a `'static` referencecrates.io · fake-static · CWE-657 | Yüksek8,0 | — | — | 25 Ağu 2021 |
31İzleyin | CVE-2019-0061İstismar yok | Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalationjuniper · junos · CWE-657 | Yüksek7,8 | — | %0,4 | 9 Eki 2019 |
30İzleyin | CVE-2026-48399İstismar yok | Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)adobe · campaign · CWE-657 | Yüksek7,5 | — | %0,9 | 3 Ağu 2026 |
30İzleyin | CVE-2023-52714İstismar yok | Vulnerability of defects introduced in the design process in the hwnff module.huawei · emui · CWE-657 | Yüksek7,5 | — | %0,3 | 7 Nis 2024 |
30İzleyin | CVE-2024-57957İstismar yok | Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affechuawei · harmonyos · CWE-657 | Yüksek7,5 | — | %0,3 | 6 Şub 2025 |
26İzleyin | CVE-2022-28244İstismar yok | Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalationadobe · acrobat dc · CWE-657 | Orta6,3 | — | %3,6 | 11 May 2022 |
22İzleyin | CVE-2019-5478İstismar yok | A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.amd · zu11eg firmware · CWE-657 | Orta5,5 | — | %0,2 | 3 Eyl 2019 |
22İzleyin | GHSA-qm5v-pj64-852jİstismar yok | Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"Packagist · passbolt/passbolt_api · CWE-657 | Orta5,5 | — | — | 20 May 2024 |
21İzleyin | CVE-2017-6032İstismar yok | A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.schneider-electric · modbus firmware · CWE-657 | Orta5,3 | — | %1,7 | 29 Haz 2017 |
21İzleyin | CVE-2021-36061İstismar yok | Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordingsadobe · connect · CWE-657 | Orta5,4 | — | %1,6 | 1 Eyl 2021 |
21İzleyin | CVE-2022-30683İstismar yok | AEM Violation of Secure Design Principles Security feature bypassadobe · experience manager · CWE-657 | Orta5,3 | — | %0,7 | 16 Eyl 2022 |
21İzleyin | CVE-2020-8133İstismar yok | A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.nextcloud · nextcloud server · CWE-657 | Orta5,3 | — | %0,7 | 9 Kas 2020 |
19İzleyin | CVE-2019-15611İstismar yok | Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when searnextcloud · nextcloud · CWE-657 | Orta4,9 | — | %1,1 | 4 Şub 2020 |
17İzleyin | CVE-2021-28583İstismar yok | Magento Commerce insecure storage of sensitive documentationmagento · magento · CWE-657 | Orta4,2 | — | %1,9 | 28 Haz 2021 |
16İzleyin | CVE-2025-54255İstismar yok | Acrobat Reader | Violation of Secure Design Principles (CWE-657)adobe · acrobat · CWE-657 | Orta4,0 | — | %0,3 | 9 Eyl 2025 |
14İzleyin | CVE-2021-44714İstismar yok | Adobe Acrobat Reader Missing Custom Protocols in Warning Message Promptsadobe · acrobat dc · CWE-657 | Düşük3,3 | — | %2,6 | 14 Oca 2022 |
- CVE-2026-3988839İzleyin
PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)
KritikCVSS 9,9İstismar yokEPSS %1praison · praisonai8 Nis 2026
- CVE-2023-2932033İzleyin
ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw
YüksekCVSS 7,8İstismar yokEPSS %5adobe · acrobat dc10 Ağu 2023
- GHSA-8xw8-mmqv-frqq32İzleyin
fake-static allows converting any reference into a `'static` reference
YüksekCVSS 8,0İstismar yokcrates.io · fake-static25 Ağu 2021
- CVE-2019-006131İzleyin
Junos OS: Insecure management daemon (MGD) configuration may allow local privilege escalation
YüksekCVSS 7,8İstismar yokEPSS %0juniper · junos9 Eki 2019
- CVE-2026-4839930İzleyin
Adobe Campaign Classic (ACC) | Violation of Secure Design Principles (CWE-657)
YüksekCVSS 7,5İstismar yokEPSS %1adobe · campaign3 Ağu 2026
- CVE-2023-5271430İzleyin
Vulnerability of defects introduced in the design process in the hwnff module.
YüksekCVSS 7,5İstismar yokEPSS %0huawei · emui7 Nis 2024
- CVE-2024-5795730İzleyin
Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affec
YüksekCVSS 7,5İstismar yokEPSS %0huawei · harmonyos6 Şub 2025
- CVE-2022-2824426İzleyin
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
OrtaCVSS 6,3İstismar yokEPSS %4adobe · acrobat dc11 May 2022
- CVE-2019-547822İzleyin
A weakness was found in Encrypt Only boot mode in Zynq UltraScale+ devices.
OrtaCVSS 5,5İstismar yokEPSS %0amd · zu11eg firmware3 Eyl 2019
- GHSA-qm5v-pj64-852j22İzleyin
Passbolt Api Tabnabbing when opening URI with menu "Open URI in a new tab"
OrtaCVSS 5,5İstismar yokPackagist · passbolt/passbolt_api20 May 2024
- CVE-2017-603221İzleyin
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol.
OrtaCVSS 5,3İstismar yokEPSS %2schneider-electric · modbus firmware29 Haz 2017
- CVE-2021-3606121İzleyin
Adobe Connect Violation of Secure Design Principles Vulnerability Can Lead To Editing Or Deleting Recordings
OrtaCVSS 5,4İstismar yokEPSS %2adobe · connect1 Eyl 2021
- CVE-2022-3068321İzleyin
AEM Violation of Secure Design Principles Security feature bypass
OrtaCVSS 5,3İstismar yokEPSS %1adobe · experience manager16 Eyl 2022
- CVE-2020-813321İzleyin
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
OrtaCVSS 5,3İstismar yokEPSS %1nextcloud · nextcloud server9 Kas 2020
- CVE-2019-1561119İzleyin
Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when sear
OrtaCVSS 4,9İstismar yokEPSS %1nextcloud · nextcloud4 Şub 2020
- CVE-2021-2858317İzleyin
Magento Commerce insecure storage of sensitive documentation
OrtaCVSS 4,2İstismar yokEPSS %2magento · magento28 Haz 2021
- CVE-2025-5425516İzleyin
Acrobat Reader | Violation of Secure Design Principles (CWE-657)
OrtaCVSS 4,0İstismar yokEPSS %0adobe · acrobat9 Eyl 2025
- CVE-2021-4471414İzleyin
Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts
DüşükCVSS 3,3İstismar yokEPSS %3adobe · acrobat dc14 Oca 2022