Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-39888CRITICALPraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (subprocess mode)EPSS 0.5%CVE-2026-45697CRITICALFormie: Pre-authenticated server-side template injection in Hidden fieldsEPSS 0.5%CVE-2026-46638MEDIUMTwig: `{% sandbox %}{% include %}` skips checkSecurity() on cached templates (incomplete fix for CVE-2024-45411)EPSS 0.5%CVE-2026-76059HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.5%CVE-2019-5024HIGHA restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical informaEPSS 0.5%CVE-2022-39011HIGHThe HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulneEPSS 0.5%CVE-2026-47305HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 0.5%CVE-2018-0250—A vulnerability in Central Web Authentication (CWA) with FlexConnect Access Points (APs) for Cisco Aironet 1560, 1810, 1810w, 1815, 1830, 18EPSS 0.5%CVE-2024-13794MEDIUMHide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page DisclosureEPSS 0.5%CVE-2023-52378CRITICALVulnerability of incorrect service logic in the WindowManagerServices module.Successful exploitation of this vulnerability may cause featureEPSS 0.5%CVE-2026-75874CRITICALSandbox escape in the Remote Settings Client componentEPSS 0.5%CVE-2026-92129HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check calls from sandboxed scripts to methods added dynamically toEPSS 0.5%CVE-2026-59207HIGHn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP ConnectorEPSS 0.4%CVE-2025-59326CRITICALCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for uEPSS 0.4%CVE-2026-29649CRITICALNEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectlEPSS 0.4%CVE-2026-92948CRITICALvm2 3.9.6 through 3.11.5 Sandbox Escape via node:testEPSS 0.4%CVE-2026-91949CRITICALFreeRDP 3.0.0 through 3.30.0 Protocol Negotiation BypassEPSS 0.4%CVE-2026-46403MEDIUMKlever-Go KVM read-only execution can commit contract delete and upgrade side effectsEPSS 0.4%CVE-2022-46762HIGHThe memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.EPSS 0.4%CVE-2022-48290CRITICALThe phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiEPSS 0.4%