Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-8401CRITICALSandbox escape in the Profile Backup componentEPSS 0.3%CVE-2026-73217HIGHCursor: Sandbox escape via tampered Python virtual environmentsEPSS 0.3%CVE-2025-49193MEDIUMMissing HTTP Security HeadersEPSS 0.3%CVE-2023-51748HIGHScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by pEPSS 0.3%CVE-2026-16370CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.3%CVE-2026-16380CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-57135HIGHPraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clientsEPSS 0.3%CVE-2024-39599MEDIUM[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.3%CVE-2026-13859CRITICALInappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2025-0276MEDIUMHCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2026-32947MEDIUMEgress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)EPSS 0.3%CVE-2026-77892MEDIUMWindows Boot Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-0277MEDIUMHCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2026-13951HIGHInsufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-47656HIGHWindows Boot Manager Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48568HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-45588HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48570HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48575HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2025-64763LOWEnvoy forwards early CONNECT data in TCP proxy modeEPSS 0.3%