Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-81376CRITICALVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2025-43273CRITICALA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandEPSS 0.6%CVE-2024-43513MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-6741MEDIUMOpenfind Mail2000 - HttpOnly flag bypassEPSS 0.6%CVE-2022-27516MEDIUMUser login brute force protection functionality bypass EPSS 0.6%CVE-2025-71352HIGHpicklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle FilesEPSS 0.6%CVE-2025-71373HIGHpicklescan - Remote Code Execution via operator.methodcaller Detection BypassEPSS 0.6%CVE-2024-26250MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-28248HIGHCilium intermittent HTTP policy bypassEPSS 0.6%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2024-33883MEDIUMThe ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.EPSS 0.6%CVE-2026-46634HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nameEPSS 0.6%CVE-2026-92122HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxedEPSS 0.6%CVE-2024-20669MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-28919MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-20665MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iEPSS 0.6%CVE-2024-0681MEDIUMPage Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism BypassEPSS 0.6%CVE-2024-0680MEDIUMWP Private Content Plus <= 3.6 - Protection Mechanism BypassEPSS 0.6%CVE-2024-20923LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions thEPSS 0.6%CVE-2023-0141MEDIUMInsufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crEPSS 0.6%