Fallos del tipo CWE-1021

215 resultados

Implementação inadequada de requisito de segurança

É quando um desenvolvedor implementa um controle de segurança ou funcionalidade crítica de forma incompleta, incorreta ou desalinhada com a intenção original. O código executa, mas não protege contra a ameaça que deveria, deixando brechas exploráveis.

Ejemplo

Um sistema implementa validação de entrada verificando apenas letras, mas esquece de validar tamanho máximo de string. Um atacante envia um payload gigante que causa buffer overflow apesar da validação existir.

Cómo mitigar

Revise a especificação de segurança contra a implementação real (code review com foco em completude). Use testes de segurança específicos (fuzzing, testes de limite) antes de deploy, não confie que 'parece estar protegido'.

CVE-2025-49139MEDIUM@haxtheweb/haxcms-nodejs Iframe Phishing vulnerabilityEPSS 0.4%CVE-2024-30109LOWLack of Clickjacking Protection vulnerability affects DRYiCE AEX v10EPSS 0.4%CVE-2025-1019MEDIUMFullscreen notification not properly displayedEPSS 0.4%CVE-2024-8388MEDIUMMultiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullEPSS 0.4%CVE-2025-64387MEDIUMCLICKJACKINGEPSS 0.4%CVE-2024-2383MEDIUMClickjacking Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2024-57369MEDIUMClickjacking vulnerability in typecho v1.2.1.EPSS 0.4%CVE-2023-36920MEDIUMClickjacking vulnerability in SAP Enable NowEPSS 0.4%CVE-2023-28159MEDIUMThe fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion orEPSS 0.3%CVE-2023-25748MEDIUMBy displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion orEPSS 0.3%CVE-2025-49191MEDIUMDashboards and iFrames can link malicious web contentEPSS 0.3%CVE-2025-41000LOWCross-Frame Scripting (XFS) in BoomCMSEPSS 0.3%CVE-2024-39320MEDIUMDiscourse allows iframe injection though default site settingEPSS 0.3%CVE-2025-24310MEDIUMImproper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attEPSS 0.3%CVE-2025-1917MEDIUMInappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2026-60370HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-49192MEDIUMClickjackingEPSS 0.3%CVE-2026-37470HIGHAn issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTEPSS 0.3%CVE-2026-22918MEDIUMAn attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously craEPSS 0.3%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.3%