Skip to main content

CWE archive

CWE-657 CVEs

Programmatic archive

18 CVEs tagged with CWE-6571 Critical, 5 High, 11 Medium, 1 Low, 0 Unrated.

CVE-2026-39888

Published Apr 8, 2026

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subpr…

CVSS 9.9 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24887

Published Apr 30, 2025

OpenCTI is an open-source cyber threat intelligence platform. In versions starting from 6.4.8 to before 6.4.10, the allow/deny lists can be bypassed, allowing a user to change att…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-57957

Published Feb 6, 2025

Vulnerability of improper log information control in the UI framework module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26139

Published May 23, 2024

OpenCTI is an open source platform allowing organizations to manage their cyber threat intelligence knowledge and observables. Due to lack of certain security controls on the prof…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-52714

Published Apr 7, 2024

Vulnerability of defects introduced in the design process in the hwnff module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30683

Published Sep 16, 2022

Adobe Experience Manager versions 6.5.13.0 (and earlier) is affected by a Violation of Secure Design Principles vulnerability that could lead to bypass the security feature of the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36061

Published Sep 1, 2021

Adobe Connect version 11.2.2 (and earlier) is affected by a secure design principles violation vulnerability via the 'pbMode' parameter. An unauthenticated attacker could leverage…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-28583

Published Jun 28, 2021

Magento versions 2.4.2 (and earlier), 2.4.1-p1 (and earlier) and 2.3.6-p1 (and earlier) are affected by a Violation of Secure Design Principles vulnerability in RMA PDF filename f…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-15611

Published Feb 4, 2020

Violation of Secure Design Principles in the iOS App 2.23.0 causes the app to leak its login and token to other Nextcloud services when search e.g. for federated users or register…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-0061

Published Oct 9, 2019

The management daemon (MGD) is responsible for all configuration and management operations in Junos OS. The Junos CLI communicates with MGD over an internal unix-domain socket and…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1