Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2025-24874MEDIUMMissing Defense in Depth Against Clickjacking in SAP Commerce BackofficeEPSS 0.3%CVE-2023-45698MEDIUMHCL Sametime is impacted by clickjackingEPSS 0.3%CVE-2025-9108MEDIUMPortabilis i-Diario Login Page ui layerEPSS 0.3%CVE-2024-55888HIGHContent Security Policy appears to be missing in software and production setupEPSS 0.3%CVE-2025-54139MEDIUMHAX CMS' application pages are vulnerable to clickjackingEPSS 0.3%CVE-2026-18534HIGHAddress bar spoofing risk in affected iOS versions of Arc SearchEPSS 0.3%CVE-2025-25213MEDIUMImproper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the cEPSS 0.3%CVE-2026-23731MEDIUMWeGIA Clickjacking VulnerabilityEPSS 0.3%CVE-2026-70486HIGHOpen WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originEPSS 0.3%CVE-2025-32385MEDIUMEspoCRM allows unrestricted Embedding in Iframe dashletEPSS 0.3%CVE-2024-53976MEDIUMUnder certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what tEPSS 0.3%CVE-2025-15032HIGHCVE-2025-15032: Increased Spoofing risk; custom new window missing about:blankEPSS 0.3%CVE-2025-27455MEDIUMCVE-2025-27455EPSS 0.3%CVE-2025-0362MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.3%CVE-2026-28971MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS EPSS 0.3%CVE-2024-6466MEDIUMNEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FEPSS 0.3%CVE-2025-1494MEDIUMIBM Cognos Command Center clickjackingEPSS 0.3%CVE-2024-0669MEDIUMCross-Frame Scripting (XFS) on Plone CMSEPSS 0.3%CVE-2026-26000MEDIUMXWiki Platform affected by click-jacking through CSS injection in commentsEPSS 0.3%CVE-2026-12348HIGHAddress Bar Spoofing in Arc Search for Android (window.open race condition)EPSS 0.3%