Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2024-33377HIGHLB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim uEPSS 0.4%CVE-2026-44727CRITICALJupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSPEPSS 0.4%CVE-2022-3260MEDIUMThe response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these EPSS 0.4%CVE-2024-28196MEDIUMClickjacking in your_spotifyEPSS 0.4%CVE-2024-11695MEDIUMA crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoEPSS 0.4%CVE-2022-32517MEDIUMA CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface uEPSS 0.4%CVE-2026-40957MEDIUMFrameable content vulnerability in the Secure Access server login pageEPSS 0.4%CVE-2025-1018HIGHFullscreen notification is not displayed when fullscreen is re-requestedEPSS 0.4%CVE-2023-34658—Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.EPSS 0.4%CVE-2024-49796MEDIUMIBM ApplinX ClickjackingEPSS 0.4%CVE-2022-45417MEDIUMService Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk fEPSS 0.4%CVE-2021-3734MEDIUMImproper Restriction of Rendered UI Layers or Frames in yourls/yourlsEPSS 0.4%CVE-2023-3140MEDIUMKNIME Hub Web Application is vulnerable to clickjackingEPSS 0.4%CVE-2022-28649MEDIUMIn JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue descriptionEPSS 0.4%CVE-2025-6983MEDIUMClickjacking vulnerability on the management web application of TP-LINK Archer C1200EPSS 0.4%CVE-2023-2265MEDIUMImproper restriction of rendered UI layers or frames could lead to clickjacking attackEPSS 0.4%CVE-2024-10004CRITICALOpening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in tEPSS 0.4%CVE-2023-0780MEDIUMImproper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpitEPSS 0.4%CVE-2024-9397MEDIUMA missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjackingEPSS 0.4%CVE-2023-4229MEDIUMioLogik 4000 Series: Session Headers Not ImplementedEPSS 0.4%