Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2024-45835LOWInsufficient Electron Fuses ConfigurationEPSS 0.2%CVE-2026-41469MEDIUMBeghelli Sicuro24 SicuroWeb Missing Content Security PolicyEPSS 0.2%CVE-2025-46281HIGHA logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2. An appEPSS 0.2%CVE-2026-79638MEDIUMDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 0.2%CVE-2026-18015CRITICALInappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbEPSS 0.2%CVE-2025-55249LOWHCL AION is affected by a Missing Security Response Headers vulnerability.EPSS 0.2%CVE-2026-44000MEDIUMvm2: sandbox boundary bypass via host Promise resolution preserving host object identityEPSS 0.2%CVE-2025-46291MEDIUMA logic issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Tahoe 26.2. An app may bypass GatekEPSS 0.2%CVE-2026-7946MEDIUMInsufficient policy enforcement in WebUI in Google Chrome on Linux, Mac, Windows, ChromeOS prior to 148.0.7778.96 allowed a remote attacker EPSS 0.2%CVE-2026-28914MEDIUMA logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5.EPSS 0.2%CVE-2026-14440HIGHCloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA recordsEPSS 0.2%CVE-2026-11288MEDIUMInsufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a craEPSS 0.2%CVE-2026-17943MEDIUMInappropriate implementation in Parser in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass content security policy vEPSS 0.2%CVE-2026-7959LOWInappropriate implementation in Navigation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendereEPSS 0.2%CVE-2025-12909MEDIUMInsufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via EPSS 0.2%CVE-2021-33081HIGHProtection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disEPSS 0.2%CVE-2026-22707MEDIUMStrapi Upload Plugin MIME Validation Bypass via Content APIEPSS 0.2%CVE-2024-20286MEDIUMCisco NX-OS Software Python Parser Escape VulnerabilityEPSS 0.2%CVE-2024-20284MEDIUMCisco NX-OS Software Python Parser Escape VulnerabilityEPSS 0.2%CVE-2026-79298HIGHAn issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and fixed in v.11.3.0.34 allows a local attcker to execute arbitrarEPSS 0.2%