VYPR

CWE-489

Active Debug Code

BaseDraft

Description

The product is released with debugging code still enabled or active.

Hierarchy (View 1000)

Parents

Children

Related attack patterns (CAPEC)

CAPEC-121 · CAPEC-661

CVEs mapped to this weakness (88)

page 5 of 5
  • CVE-2026-27131MedMar 23, 2026
    risk 0.29cvss 5.5epss 0.00

    The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key,…

  • CVE-2022-38453LowSep 13, 2022
    risk 0.20cvss 3.0epss 0.00

    Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional…

  • CVE-2022-27597LowMar 29, 2023
    risk 0.18cvss 2.7epss 0.01

    A vulnerability has been reported to affect QNAP operating systems. If exploited, the out-of-bounds read vulnerability allows remote authenticated administrators to get secret values. The vulnerability affects the following QNAP operating systems: QTS, QuTS hero, QuTScloud, QVP…

  • CVE-2026-65893HigJul 27, 2026
    risk 0.00cvss epss 0.00

    This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecure debug feature enabled in the firmware. An attacker with physical access could exploit this vulnerability by placing arbitrary code on removable media and triggering their execution through the debug…

  • CVE-2026-58378HigJul 9, 2026
    risk 0.00cvss 8.8epss 0.00

    Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim allows access.

  • CVE-2026-58191MedJul 8, 2026
    risk 0.00cvss 6.5epss 0.00

    Appium is a cross-platform automation framework for all kinds of apps, built on top of the W3C WebDriver protocol. Prior to 10.7.0, Appium's base-driver unconditionally mounts the /test/guinea-pig, /test/guinea-pig-scrollable, and /test/guinea-pig-app-banner routes, and…

  • CVE-2026-59092HigJul 2, 2026
    risk 0.00cvss 7.7epss 0.00

    JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics endpoints by exploiting improper handler registration on the shared http.DefaultServeMux. Attackers…

  • CVE-2025-46674LowApr 27, 2025
    risk 0.00cvss 3.5epss 0.01

    NASA CryptoLib before 1.3.2 uses Extended Procedures that are a Work in Progress (not intended for use during flight), potentially leading to a keystream oracle.