Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-489

Active Debug Code

The product is released with debugging code still enabled or active.

84
Assigned CVEs
194th
Commonality Rank
7.7
Avg CVSS
0.0%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-489 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 20, 2017
8 years ago
Most Recent CVE
Jul 9, 2026
15 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

84 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-32645CRITICAL
A leftover debug code vulnerability exists in the httpd debug credentials functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to authentication
Oct 11, 20239.860NONO
CVE-2017-5259HIGH
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, an undocumented, root-privilege administration web shell is available using the HTTP path https://<device-ip-or
Dec 20, 20178.859NOYES
CVE-2024-9643CRITICAL
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web server. An attacker with knowledge
Feb 4, 20259.843NOYES
CVE-2026-49188CRITICAL
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
Jun 4, 20269.838NONO
CVE-2026-58378HIGH
Allwinner H616 TV Box TV98 has ADB enabled and exposed to the network on production. An attacker could request for ADB authorization and gain root level privileges if the victim al
Jul 9, 20268.837NONO
CVE-2026-59092HIGH
JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to access sensitive debug and metrics e
Jul 2, 20267.734NONO
CVE-2026-9133HIGH
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate valid
May 20, 20267.733NONO
CVE-2026-40035CRITICAL
Unfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by default. The debug configuration value is read as a st
Apr 8, 20269.132NONO
CVE-2022-20649HIGH
A vulnerability in Cisco&nbsp;RCM for Cisco&nbsp;StarOS Software could allow an unauthenticated, remote attacker to perform remote code execution on the application with root-level
Nov 15, 20248.132NONO
CVE-2022-32585CRITICAL
A command execution vulnerability exists in the clish art2 functionality of Robustel R1510 3.3.0. A specially-crafted network request can lead to arbitrary command execution. An at
Jun 30, 20229.832NONO
View all 84 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
25%
16%
6.0-6.9
18%
26%
7.0-7.9
24%
11%
8.0-8.9
21%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
1.2% of CVEs· 89th percentile
Nuclei
1 CVE
1.2% of CVEs· 86th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products