Weaknesses of type CWE-693

836 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2021-31386MEDIUMJunos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.EPSS 0.7%CVE-2026-26332CRITICALvm2: Sandbox EscapeEPSS 0.7%CVE-2022-43422MEDIUMJenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executEPSS 0.7%CVE-2024-38070HIGHWindows LockDown Policy (WLDP) Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-47544CRITICALAn issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.EPSS 0.7%CVE-2022-43424MEDIUMJenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can beEPSS 0.7%CVE-2026-18428HIGHSQL Query Validation Bypass in OpenSearch Direct QueryEPSS 0.7%CVE-2023-0085MEDIUMMetform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection BypassEPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2024-38203MEDIUMWindows Package Library Manager Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43434MEDIUMJenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generaEPSS 0.7%CVE-2025-21384HIGHAzure Health Bot Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-25056CRITICALn8n Arbitrary File Write leading to RCE in n8n Merge NodeEPSS 0.7%CVE-2025-21346HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2026-22686CRITICALSandbox Escape via Host Error Prototype Chain in enclave-vmEPSS 0.7%CVE-2019-13516In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection settinEPSS 0.7%CVE-2022-43435MEDIUMJenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.7%CVE-2025-27665CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Antivirus Protection aEPSS 0.7%CVE-2023-30851LOWPotential HTTP policy bypass when using header rules in CiliumEPSS 0.7%CVE-2024-5691MEDIUMBy tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would EPSS 0.7%