Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-30938MEDIUMParse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placementEPSS 0.4%CVE-2026-54981HIGHVisual Studio Code Python Extension Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-57136HIGHPraisonAI SandboxExecutor allowedCommands bypass via shell chainingEPSS 0.4%CVE-2024-8811HIGHWinZip Mark-of-the-Web Bypass VulnerabilityEPSS 0.4%CVE-2026-16377CRITICALMitigation bypass in the PDF Viewer componentEPSS 0.4%CVE-2026-16383CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2026-45733HIGHTrilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop appEPSS 0.4%CVE-2024-24983HIGHProtection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may alloEPSS 0.4%CVE-2025-50327HIGHAn issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypEPSS 0.4%CVE-2025-71322HIGHPickleScan - Unsafe Globals Check Bypass via pty.spawn FunctionEPSS 0.4%CVE-2026-59223MEDIUMOpen WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingEPSS 0.4%CVE-2026-93605CRITICALvm2 NodeVM before 3.12.1 Remote Code Execution via child_processEPSS 0.4%CVE-2025-60711MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-27383MEDIUMProtection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a pEPSS 0.4%CVE-2026-14625MEDIUMNousResearch hermes-agent server.py shell.exec protection mechanismEPSS 0.4%CVE-2026-47686CRITICALvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCEEPSS 0.4%CVE-2018-11460A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2026-16382CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.4%CVE-2018-11459A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2025-48626HIGHIn multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could EPSS 0.4%