Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-2803HIGHInformation disclosure, mitigation bypass in the Settings UI componentEPSS 0.3%CVE-2020-7320MEDIUMProtection Mechanism Failure in ENS for WindowsEPSS 0.3%CVE-2026-22013MEDIUMVulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). EPSS 0.3%CVE-2026-17776MEDIUMPolicy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to poteEPSS 0.3%CVE-2026-74883HIGHopenssl_encrypt before 1.4.0 Sandbox Bypass via pathlib and ioEPSS 0.3%CVE-2026-0620MEDIUML2TP over IPSec Encryption Failure on ArcherAXE75EPSS 0.3%CVE-2026-8018HIGHInsufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbEPSS 0.3%CVE-2026-92959HIGHvm2 before 3.11.8 allowAsync Bypass via Promise ThenableEPSS 0.3%CVE-2026-11263MEDIUMInsufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had coEPSS 0.3%CVE-2025-20347MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.3%CVE-2026-13862MEDIUMInsufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an aEPSS 0.3%CVE-2026-32946MEDIUMEgress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)EPSS 0.3%CVE-2022-26774HIGHA logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able EPSS 0.3%CVE-2026-14058MEDIUMInsufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policEPSS 0.3%CVE-2026-12315CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-16394CRITICALMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2026-16406CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-86800MEDIUMWP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility CheckEPSS 0.3%CVE-2026-86796MEDIUMWP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request ParametersEPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%