Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2025-64763LOWEnvoy forwards early CONNECT data in TCP proxy modeEPSS 0.3%CVE-2024-37182MEDIUMLack of permissions prompting when opening external URLsEPSS 0.3%CVE-2026-50545CRITICALFission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverEPSS 0.3%CVE-2026-74957HIGHMitigation bypass in the Safe Browsing componentEPSS 0.3%CVE-2026-54013HIGHOpen WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUIEPSS 0.3%CVE-2026-69278HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-10950MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2026-10944MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2023-0002MEDIUMCortex XDR Agent: Product Disruption by Local Windows UserEPSS 0.3%CVE-2025-44090HIGHAn issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%CVE-2026-79006MEDIUMProtection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy EPSS 0.3%CVE-2024-6153HIGHParallels Desktop Updater Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.3%CVE-2024-38874MEDIUMAn issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the maEPSS 0.3%CVE-2026-8969HIGHMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2023-20573LOWDebug Exception Delivery in Secure Nested PagingEPSS 0.3%CVE-2026-53508MEDIUMoasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)EPSS 0.3%CVE-2025-44089HIGHAn issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%CVE-2025-48534HIGHIn getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. ThisEPSS 0.3%CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.3%CVE-2024-46976MEDIUMCircumvention of cross site scripting Protection in @backstage/plugin-techdocs-backendEPSS 0.3%