Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2025-65318CRITICALWhen using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-WebEPSS 0.6%CVE-2024-27713HIGHAn issue in Eskooly Free Online School management Software v.3.0 and before allows a remote attacker to escalate privileges via the HTTP ResEPSS 0.6%CVE-2024-33903MEDIUMIn CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part because the collision EPSS 0.5%CVE-2022-43433MEDIUMJenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.5%CVE-2024-43645MEDIUMWindows Defender Application Control (WDAC) Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-72781HIGHCraft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox EscapeEPSS 0.5%CVE-2026-19168HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.5%CVE-2024-43584HIGHWindows Scripting Engine Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2026-19150HIGHInappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sanEPSS 0.5%CVE-2026-25115CRITICALn8n is vulnerable to Python sandbox escapeEPSS 0.5%CVE-2022-33942HIGHProtection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potentially enable escalatEPSS 0.5%CVE-2024-0101HIGHNVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enEPSS 0.5%CVE-2022-42801HIGHA logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS EPSS 0.5%CVE-2024-23499HIGHProtection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before versEPSS 0.5%CVE-2024-56326MEDIUMJinja has a sandbox breakout through indirect reference to format methodEPSS 0.5%CVE-2023-3089HIGHOcp & fips modeEPSS 0.5%CVE-2026-93606CRITICALvm2 before 3.12.1 Sandbox Escape via Promise Symbol.speciesEPSS 0.5%CVE-2023-4466LOWPoly CCX 400/CCX 600/Trio 8800/Trio C60 Web Interface protection mechanismEPSS 0.5%CVE-2026-57280HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the elements of typed foEPSS 0.5%CVE-2026-33622MEDIUMA PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript ExecutionEPSS 0.5%