Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2025-59950MEDIUMFreshRSS: Double clickjacking can lead to privilege escalationEPSS 0.3%CVE-2025-52987MEDIUMParagon Automation: A clickjacking vulnerability in the web server configuration has been addressedEPSS 0.3%CVE-2024-54110MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2025-57769MEDIUMFressRSS: Clickjacking can lead to XSS and/or privilege escalationEPSS 0.3%CVE-2024-7523MEDIUMA select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.3%CVE-2025-14373MEDIUMInappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spooEPSS 0.3%CVE-2023-47774MEDIUMWordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerabilityEPSS 0.3%CVE-2026-38979MEDIUMajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTEPSS 0.3%CVE-2025-14812HIGHAddress bar spoofing risk in Arc Search on iOSEPSS 0.3%CVE-2025-5267MEDIUMClickjacking vulnerability could have led to leaking saved payment card detailsEPSS 0.3%CVE-2026-9396MEDIUMBesen BS20 EV Charging Station Firmware Version Check ui layerEPSS 0.3%CVE-2021-29827MEDIUMIBM InfoSphere Information Server clickjackingEPSS 0.3%CVE-2026-74958HIGHInformation disclosure in the WebRTC componentEPSS 0.3%CVE-2025-6434MEDIUMHTTPS-Only exception screen lacked anti-clickjacking delayEPSS 0.3%CVE-2025-31138MEDIUMtarteaucitron.js allows UI manipulation via unrestricted CSS injectionEPSS 0.3%CVE-2025-54527MEDIUMIn JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allowEPSS 0.3%CVE-2025-7903MEDIUMyangzongzhuan RuoYi Image Source ui layerEPSS 0.3%CVE-2023-6093MEDIUMOnCell G3150A-LTE Series: Clickjacking VulnerabilityEPSS 0.3%CVE-2025-0546MEDIUMXSS in Mevzuattr Software's MevzuatTREPSS 0.3%CVE-2023-7013MEDIUMInappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof securityEPSS 0.2%