Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2025-65318CRITICALWhen using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-WebEPSS 0.6%CVE-2024-27713HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP ResEPSS 0.6%CVE-2024-33903MEDIUMIn CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision EPSS 0.5%CVE-2022-43433MEDIUMJenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.5%CVE-2024-43645MEDIUMWindows Defender Application Control (WDAC) Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-72781HIGHCraft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox EscapeEPSS 0.5%CVE-2026-19168HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.5%CVE-2024-43584HIGHWindows Scripting Engine Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-19150HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.5%CVE-2026-25115CRITICALn8n is vulnerable to Python sandbox escapeEPSS 0.5%CVE-2022-33942HIGHProtection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalatEPSS 0.5%CVE-2024-0101HIGHNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enEPSS 0.5%CVE-2022-42801HIGHA logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS EPSS 0.5%CVE-2024-23499HIGHProtection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before versEPSS 0.5%CVE-2024-56326MEDIUMJinja has a sandbox breakout through indirect reference to format methodEPSS 0.5%CVE-2023-3089HIGHOcp & fips modeEPSS 0.5%CVE-2026-93606CRITICALvm2 before 3.12.1 Sandbox Escape via Promise Symbol.speciesEPSS 0.5%CVE-2023-4466LOWPoly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanismEPSS 0.5%CVE-2026-57280HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed foEPSS 0.5%CVE-2026-33622MEDIUMA PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript ExecutionEPSS 0.5%