Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.3%CVE-2022-42848HIGHA logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS 15.7.2, tvOS 16.2. EPSS 0.3%CVE-2026-74790CRITICALScriban before 7.0.0 MemberFilter Bypass via TemplateContext CacheEPSS 0.3%CVE-2025-50325MEDIUMBandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-WEPSS 0.3%CVE-2026-79686HIGHDell PowerStore contains a Protection Mechanism Failure vulnerability. An authenticated user with limited privileges could potentially exploEPSS 0.3%CVE-2026-47139HIGHvm2: NodeVM network builtin exclusions bypass via internal _http_client and _http_serverEPSS 0.3%CVE-2026-92079CRITICALMitigation bypass in the Widget: Win32 componentEPSS 0.3%CVE-2026-79919MEDIUMMaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)EPSS 0.3%CVE-2026-54694CRITICALNationalSecurityAgency/skills-service has Stored XSS via User Registration Enabling Admin Account TakeoverEPSS 0.3%CVE-2026-92057CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-16407CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.3%CVE-2024-25744HIGHIn the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tEPSS 0.3%CVE-2022-48219MEDIUMPotential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusioEPSS 0.3%CVE-2026-26994MEDIUMuTLS ServerHellos are accepted without checking TLS 1.3 downgrade canariesEPSS 0.3%CVE-2022-46329HIGHProtection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation ofEPSS 0.3%CVE-2026-17856CRITICALInappropriate implementation in Network in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renEPSS 0.3%CVE-2026-48033HIGHHulumi: Policy packs bypassed by a forged Pulumi-URN logical nameEPSS 0.3%CVE-2026-17865CRITICALInappropriate implementation in Crypto in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2025-50897MEDIUMA vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translationsEPSS 0.3%CVE-2026-50564CRITICALFission Environment CRD podspec passthrough enables hostPID/hostNetwork/privileged pods, node escapeEPSS 0.3%