Weaknesses of type CWE-1021

216 results

Implementação inadequada de mecanismo de segurança

Ocorre quando um desenvolvedor implementa um controle de segurança (autenticação, criptografia, validação, etc.) de forma incorreta ou incompleta, deixando brechas no mecanismo pretendido. A lógica pode estar presente, mas falha na prática porque não cobre todos os casos, usa configurações fracas ou não segue padrões estabelecidos.

Example

Uma aplicação implementa autenticação de dois fatores, mas aceita qualquer código OTP com mais de 4 dígitos sem validar se é realmente o esperado; ou usa MD5 para hash de senhas porque 'é rápido'. O mecanismo existe, mas não funciona corretamente.

How to mitigate

Use bibliotecas e frameworks de segurança consolidados em vez de reinventar a roda; revise implementações críticas (auth, crypto, validação) contra padrões da indústria (OWASP, NIST); execute testes de segurança específicos e code review com foco em lógica de controles, não apenas sintaxe.

CVE-2025-14809HIGHAddress bar spoofing risk in ArcSearch on AndroidEPSS 0.2%CVE-2025-1923MEDIUMInappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to instaEPSS 0.2%CVE-2026-87538MEDIUMClickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveragEPSS 0.2%CVE-2024-56435MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-63522MEDIUMReverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management functionEPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2024-54112MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-59849MEDIUMHCL BigFix Remote Control is vulnerable to an insecure CSP configurationEPSS 0.2%CVE-2025-59479MEDIUMCHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a user clicks on content EPSS 0.2%CVE-2024-56436MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2026-87655MEDIUMClickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elemenEPSS 0.2%CVE-2025-30191MEDIUMMalicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensEPSS 0.2%CVE-2026-84139CRITICALClickjacking issue in the DOM: Events componentEPSS 0.2%CVE-2024-13066MEDIUMiFrame Injection in Akinsoft's LimonDeskEPSS 0.2%CVE-2025-36149MEDIUMIBM Concert Software clickjackingEPSS 0.2%CVE-2026-70600LOWElectron: Cross-origin iframe can position native autofill popupEPSS 0.2%CVE-2026-74980MEDIUMClickjacking issue in the Downloads component in Firefox for AndroidEPSS 0.2%CVE-2026-16397MEDIUMClickjacking issue in the WebExtensions component in Firefox for AndroidEPSS 0.2%CVE-2026-2378HIGHAddress bar spoofing risk in ArcSearch on AndroidEPSS 0.2%CVE-2025-58405MEDIUMLack of protection mechanisms against Clickjacking attacksEPSS 0.2%