Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2025-49139MEDIUM@haxtheweb/haxcms-nodejs Iframe Phishing vulnerabilityEPSS 0.4%CVE-2024-30109LOWLack of Clickjacking Protection vulnerability affects DRYiCE AEX v10EPSS 0.4%CVE-2025-1019MEDIUMFullscreen notification not properly displayedEPSS 0.4%CVE-2024-8388MEDIUMMultiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullEPSS 0.4%CVE-2025-64387MEDIUMCLICKJACKINGEPSS 0.4%CVE-2024-2383MEDIUMClickjacking Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2024-57369MEDIUMClickjacking vulnerability in typecho v1.2.1.EPSS 0.4%CVE-2023-36920MEDIUMClickjacking vulnerability in SAP Enable NowEPSS 0.4%CVE-2023-28159MEDIUMThe fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion orEPSS 0.3%CVE-2023-25748MEDIUMBy displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion orEPSS 0.3%CVE-2025-49191MEDIUMDashboards and iFrames can link malicious web contentEPSS 0.3%CVE-2025-41000LOWCross-Frame Scripting (XFS) in BoomCMSEPSS 0.3%CVE-2024-39320MEDIUMDiscourse allows iframe injection though default site settingEPSS 0.3%CVE-2025-24310MEDIUMImproper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attEPSS 0.3%CVE-2025-1917MEDIUMInappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2026-60370HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-49192MEDIUMClickjackingEPSS 0.3%CVE-2026-37470HIGHAn issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTEPSS 0.3%CVE-2026-22918MEDIUMAn attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously craEPSS 0.3%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.3%