Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2026-11234MEDIUMInappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the rendeEPSS 0.2%CVE-2026-8585HIGHInappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-61437HIGHPraisonAI before 1.6.78 Remote Code Execution via tools.pyEPSS 0.2%CVE-2026-91796MEDIUMFoxit PDF Editor/Reader importIcon NTLM Response Information Disclosure VulnerabilityEPSS 0.2%CVE-2022-20562LOWIn various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. EPSS 0.2%CVE-2021-33079MEDIUMProtection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disEPSS 0.2%CVE-2024-24980MEDIUMProtection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enaEPSS 0.2%CVE-2026-7952MEDIUMInsufficient policy enforcement in Extensions in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the rendEPSS 0.2%CVE-2026-11684LOWInsufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utilitEPSS 0.2%CVE-2026-58052MEDIUM7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name CollisionEPSS 0.2%CVE-2021-26355MEDIUMInsufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in EPSS 0.2%CVE-2024-51481LOWNix allows macOS sandbox escape via built-in buildersEPSS 0.2%CVE-2026-35408HIGHDirectus is Missing Cross-Origin Opener PolicyEPSS 0.2%CVE-2026-11266MEDIUMInappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via aEPSS 0.2%CVE-2025-14095MEDIUMPrivilege boundary violation in Radiometer ProductsEPSS 0.2%CVE-2026-92962LOWvm2 before 3.11.4 Defense Invariant Violation via setup-sandbox.jsEPSS 0.2%CVE-2025-0575LOWUnion Bank of India Vyom Rooting Detection protection mechanismEPSS 0.2%CVE-2026-28849MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. A maliciouEPSS 0.2%CVE-2026-28900MEDIUMA file quarantine bypass was addressed with additional checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS TahoeEPSS 0.2%CVE-2026-5911MEDIUMPolicy bypass in ServiceWorkers in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass content security policy via a crEPSS 0.2%