CWE-657

Violation of Secure Design Principles

Parent: CWE-710 - Improper Adherence to Coding Standards

The product violates well-established principles for secure design.

18 vulnerabilities with CWE-657
CVE-2026-39888 CRITICAL
PraisonAIAgents <1.5.115 execute_code - Sandbox Escape
CVSS 9.9
CVE-2025-54255 MEDIUM
Acrobat Reader <24.001.30254-25.001.20672 - Security Feature Bypass
CVSS 4.0
CVE-2025-24887 MEDIUM
OpenCTI <6.4.10 - Privilege Escalation
CVSS 6.3
CVE-2024-57957 MEDIUM
HarmonyOS - Sensitive Information Exposure via UI Framework Log Insertion
CVSS 6.6
CVE-2024-33849 MEDIUM
CI-Out-of-Office Manager <6.0.0.77 - Info Disclosure
CVSS 6.5
CVE-2024-26139 HIGH
OpenCTI < 5.12.31 - Authenticated Privilege Escalation via Profile Edit Functionality
CVSS 8.3
CVE-2023-52714 HIGH
Huawei EMUI and HarmonyOS - Information Disclosure via hwnff Module Design Flaw
CVSS 7.5
CVE-2023-29320 HIGH
Adobe Acrobat Reader <23.003.20244,20.005.30467 - RCE
CVSS 7.8
CVE-2022-30683 MEDIUM
Adobe Experience Manager <6.5.13.0 - Auth Bypass
CVSS 5.3
CVE-2022-28244 MEDIUM
Acrobat Reader DC <22.001.20085 - CSRF
CVSS 6.3
CVE-2021-44714 LOW
Acrobat Reader DC <21.007.20099 - Security Feature Bypass
CVSS 2.5
CVE-2021-36061 MEDIUM
Adobe Connect <11.2.2 - Info Disclosure
CVSS 5.4
CVE-2021-28583 HIGH
Magento <2.4.2, 2.4.1-p1, 2.3.6-p1 - Info Disclosure
CVSS 7.5
CVE-2020-8133 MEDIUM
Nextcloud Server <19.0.1 - Info Disclosure
CVSS 5.3
CVE-2019-15611 MEDIUM
Nextcloud iOS App < 2.24.0 - Credential Leak via Federated Search and Push Notification Registration
CVSS 4.9
CVE-2019-0061 HIGH
Junos OS - Local Privilege Escalation via MGD Unix-Domain Socket Misconfiguration
CVSS 7.8
CVE-2019-5478 MEDIUM
AMD Zynq UltraScale+ Firmware - Insufficient Verification of Data Authenticity in Encrypt Only Boot Mode
CVSS 5.5
CVE-2017-6032 MEDIUM
Schneider Electric Modicon - Info Disclosure
CVSS 5.3
Details
Vulnerabilities 18