Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2024-0747MEDIUMWhen a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child ContEPSS 0.6%CVE-2025-3114CRITICALSpotfire Code Execution VulnerabilityEPSS 0.6%CVE-2023-0131MEDIUMInappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to bypass file download EPSS 0.6%CVE-2026-92124HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from aEPSS 0.6%CVE-2026-92123HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, pEPSS 0.6%CVE-2025-48800MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2022-41979MEDIUMProtection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalatioEPSS 0.6%CVE-2024-21423MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-28286MEDIUMMicrosoft Edge (Chromium-based) Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-92944CRITICALvm2 3.10.2 through 3.11.6 Sandbox Escape via Promise ProtectorEPSS 0.6%CVE-2025-43413HIGHAn access issue was addressed with additional sandbox restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1, macOS Sequoia 15.7.2, mEPSS 0.6%CVE-2022-43432MEDIUMJenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user-generated content iEPSS 0.6%CVE-2026-76825HIGHRestrictedPython: Sandbox escape via string.Formatter field resolutionEPSS 0.6%CVE-2025-48003MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2020-28396A vulnerability has been identified in SICAM A8000 CP-8000 (All versions < V16), SICAM A8000 CP-8021 (All versions < V16), SICAM A8000 CP-80EPSS 0.6%CVE-2025-50329CRITICALAn issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code vEPSS 0.6%CVE-2025-65319CRITICALWhen using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-WeEPSS 0.6%CVE-2026-14535HIGHFickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()EPSS 0.6%CVE-2020-16198MEDIUMPhilips Clinical Collaboration Platform Protection Mechanism FailureEPSS 0.6%CVE-2026-34208CRITICALSandboxJS: Sandbox integrity escapeEPSS 0.6%