Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-92778MEDIUMCMAK through 3.0.0.6 Feature Gate Bypass via HTML Form RoutesEPSS 0.3%CVE-2026-74938CRITICALMitigation bypass in the JavaScript: GC componentEPSS 0.3%CVE-2020-3458MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass VulnerabilitiesEPSS 0.3%CVE-2026-17659MEDIUMInappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-45656HIGHUEFI Secure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-92066CRITICALSandbox escape in the Profile Backup componentEPSS 0.3%CVE-2026-14097CRITICALInappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-14050MEDIUMInsufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2026-13910MEDIUMInsufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin dEPSS 0.3%CVE-2026-14059MEDIUMInsufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origEPSS 0.3%CVE-2026-39452MEDIUMProtection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escaEPSS 0.3%CVE-2026-28500HIGHONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain AttackEPSS 0.3%CVE-2026-57120MEDIUMPraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunderEPSS 0.3%CVE-2025-12094MEDIUMOOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthenticated IP Header SpoofingEPSS 0.3%CVE-2019-19278A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-..EPSS 0.3%CVE-2026-76827MEDIUMSearch-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)EPSS 0.3%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.3%CVE-2025-52951MEDIUMJunos OS: IPv6 firewall filter fails to match payload-protocolEPSS 0.3%CVE-2026-16390CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-84809HIGHTencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python BytecodeEPSS 0.3%