Weaknesses of type CWE-358

114 results

Verificação de Segurança Incompleta ou Inadequada

A aplicação implementa uma validação de segurança, mas ela é insuficiente, incompleta ou contornável — deixando brechas que um atacante consegue explorar. O código tenta proteger, mas falha em cobrir todos os cenários ou não valida corretamente, permitindo acesso não autorizado ou execução maliciosa.

Example

Um sistema valida se o usuário está autenticado antes de acessar um recurso, mas não verifica se ele tem permissão específica para aquele recurso; ou uma API verifica o token JWT, mas não valida a assinatura corretamente, permitindo tokens falsificados.

How to mitigate

Implemente validações em múltiplas camadas (autenticação + autorização), revise a lógica de segurança com testes de contorno, use bibliotecas consolidadas (OAuth 2.0, OWASP ESAPI) e realize code review focado em edge cases e cenários de bypass.

CVE-2023-28113MEDIUMrussh may use insecure Diffie-Hellman keysEPSS 0.6%CVE-2020-1761A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaEPSS 0.6%CVE-2022-2324Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service iEPSS 0.6%CVE-2023-22393HIGHJunos OS and Junos OS Evolved: RPD crash upon receipt of BGP route with invalid next-hop EPSS 0.6%CVE-2025-8204LOWComodo Dragon HSTS security checkEPSS 0.6%CVE-2024-6995HIGHInappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a userEPSS 0.6%CVE-2025-21267MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.6%CVE-2024-33510LOWAn improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS versEPSS 0.6%CVE-2026-45109HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesEPSS 0.6%CVE-2022-22156MEDIUMJunos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URLEPSS 0.5%CVE-2024-6772HIGHInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory accessEPSS 0.5%CVE-2026-57915HIGHApache Kerby: Kerberos Pre-Authentication BypassEPSS 0.5%CVE-2024-7003MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in spEPSS 0.5%CVE-2025-62583CRITICALWhale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.EPSS 0.5%CVE-2026-40597HIGHMantisBT has a Content Security Policy bypass via attachmentsEPSS 0.5%CVE-2026-29103CRITICALSuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner BypassEPSS 0.5%CVE-2021-26105MEDIUMA stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and belowEPSS 0.5%CVE-2021-42017MEDIUMA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUEPSS 0.5%CVE-2026-1486HIGHOrg.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grantEPSS 0.5%CVE-2026-12577HIGHDVP80ES3 Improperly Implemented Security Check for Standard vulnerabilityEPSS 0.4%