Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-81376CRITICALVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2025-43273CRITICALA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandEPSS 0.6%CVE-2024-43513MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-6741MEDIUMOpenfind Mail2000 - HttpOnly flag bypassEPSS 0.6%CVE-2022-27516MEDIUMUser login brute force protection functionality bypass EPSS 0.6%CVE-2025-71352HIGHpicklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle FilesEPSS 0.6%CVE-2025-71373HIGHpicklescan - Remote Code Execution via operator.methodcaller Detection BypassEPSS 0.6%CVE-2024-26250MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-28248HIGHCilium intermittent HTTP policy bypassEPSS 0.6%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2024-33883MEDIUMThe ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.EPSS 0.6%CVE-2026-46634HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nameEPSS 0.6%CVE-2026-92122HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxedEPSS 0.6%CVE-2024-20669MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-28919MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-20665MEDIUMThis issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iEPSS 0.6%CVE-2024-0681MEDIUMPage Restriction WordPress (WP) – Protect WP Pages/Post <= 1.3.4 - Protection Mechanism BypassEPSS 0.6%CVE-2024-0680MEDIUMWP Private Content Plus <= 3.6 - Protection Mechanism BypassEPSS 0.6%CVE-2024-20923LOWVulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). Supported versions thEPSS 0.6%CVE-2023-0141MEDIUMInsufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-origin data via a crEPSS 0.6%