Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-53853HIGHOpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOSEPSS 0.3%CVE-2022-4100MEDIUMWP Cerber Security <= 9.4 - IP Protection BypassEPSS 0.3%CVE-2025-14302HIGHGIGABYTE|Motherboard - Protection Mechanism FailureEPSS 0.3%CVE-2025-65100MEDIUMSecurity Snapshot May Use Unintended Timestamp When Only ISAR_APT_SNAPSHOT_DATE Is SetEPSS 0.3%CVE-2025-14303HIGHMSI|Motherboard - Protection Mechanism FailureEPSS 0.3%CVE-2024-45833MEDIUMMobile password gets saved in dictionary under conditionsEPSS 0.3%CVE-2026-14037CRITICALInsufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-52873MEDIUMStreambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electron RendererEPSS 0.3%CVE-2026-14120CRITICALInappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.3%CVE-2025-12554MEDIUMMissing Security HeadersEPSS 0.3%CVE-2026-14017CRITICALInappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendereEPSS 0.3%CVE-2026-13909CRITICALInsufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2026-92019HIGHMitigation bypass in the Remote Settings Client componentEPSS 0.3%CVE-2026-8958HIGHInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.3%CVE-2025-6427CRITICALconnect-src Content Security Policy restriction could be bypassedEPSS 0.3%CVE-2026-55366CRITICALIn IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalationEPSS 0.3%CVE-2026-74959CRITICALMitigation bypass in the Storage: Cache API componentEPSS 0.3%CVE-2023-45372An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.EPSS 0.3%CVE-2026-45770HIGHSuricata lua: excessive flow variable registration can bypass sandboxEPSS 0.3%CVE-2026-17779MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation viEPSS 0.3%