Fallos del tipo CWE-358

114 resultados

Verificação de segurança incompleta ou inadequada para padrão

A aplicação implementa um controle ou validação de segurança, mas de forma insuficiente ou que não cobre todos os casos necessários conforme o padrão esperado. Isso deixa brechas por onde um atacante consegue contornar a proteção ou explorar cenários não previstos na validação.

Ejemplo

Um sistema valida se um arquivo tem extensão .pdf antes de aceitar upload, mas não verifica o conteúdo real do arquivo — atacante envia um executável renomeado para .pdf e consegue executá-lo. Ou um serviço autentica por IP do cliente, mas não valida o token de sessão, deixando a porta aberta para roubo de sessão.

Cómo mitigar

Implemente validações em profundidade (validar não só formato, mas conteúdo, contexto e intenção), siga padrões consolidados de segurança da sua stack (OWASP, RFC de autenticação, etc) e realize testes de contorno — tenha alguém tentando quebrar cada verificação. Code review focado em completude de controles também é crítico.

CVE-2023-28113MEDIUMrussh may use insecure Diffie-Hellman keysEPSS 0.6%CVE-2020-1761A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaEPSS 0.6%CVE-2022-2324Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service iEPSS 0.6%CVE-2023-22393HIGHJunos OS and Junos OS Evolved: RPD crash upon receipt of BGP route with invalid next-hop EPSS 0.6%CVE-2025-8204LOWComodo Dragon HSTS security checkEPSS 0.6%CVE-2024-6995HIGHInappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a userEPSS 0.6%CVE-2025-21267MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.6%CVE-2024-33510LOWAn improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS versEPSS 0.6%CVE-2026-45109HIGHNext.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routesEPSS 0.6%CVE-2022-22156MEDIUMJunos OS: Certificate validation is skipped when fetching system scripts from a HTTPS URLEPSS 0.5%CVE-2024-6772HIGHInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory accessEPSS 0.5%CVE-2026-57915HIGHApache Kerby: Kerberos Pre-Authentication BypassEPSS 0.5%CVE-2024-7003MEDIUMInappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in spEPSS 0.5%CVE-2025-62583CRITICALWhale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.EPSS 0.5%CVE-2026-40597HIGHMantisBT has a Content Security Policy bypass via attachmentsEPSS 0.5%CVE-2026-29103CRITICALSuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner BypassEPSS 0.5%CVE-2021-26105MEDIUMA stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and belowEPSS 0.5%CVE-2021-42017MEDIUMA vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUEPSS 0.5%CVE-2026-1486HIGHOrg.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grantEPSS 0.5%CVE-2026-12577HIGHDVP80ES3 Improperly Implemented Security Check for Standard vulnerabilityEPSS 0.4%