Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-30938MEDIUMParse Server has denylist `requestKeywordDenylist` keyword scan bypass through nested object placementEPSS 0.4%CVE-2026-54981HIGHVisual Studio Code Python Extension Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-57136HIGHPraisonAI SandboxExecutor allowedCommands bypass via shell chainingEPSS 0.4%CVE-2024-8811HIGHWinZip Mark-of-the-Web Bypass VulnerabilityEPSS 0.4%CVE-2026-16377CRITICALMitigation bypass in the PDF Viewer componentEPSS 0.4%CVE-2026-16383CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.4%CVE-2026-45733HIGHTrilium: Stored XSS in note icon rendering leads to Remote Code Execution in Electron desktop appEPSS 0.4%CVE-2024-24983HIGHProtection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may alloEPSS 0.4%CVE-2025-50327HIGHAn issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypEPSS 0.4%CVE-2025-71322HIGHPickleScan - Unsafe Globals Check Bypass via pty.spawn FunctionEPSS 0.4%CVE-2026-59223MEDIUMOpen WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingEPSS 0.4%CVE-2026-93605CRITICALvm2 NodeVM before 3.12.1 Remote Code Execution via child_processEPSS 0.4%CVE-2025-60711MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2023-27383MEDIUMProtection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a pEPSS 0.4%CVE-2026-14625MEDIUMNousResearch hermes-agent server.py shell.exec protection mechanismEPSS 0.4%CVE-2026-47686CRITICALvm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCEEPSS 0.4%CVE-2018-11460—A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2026-16382CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.4%CVE-2018-11459—A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2025-48626HIGHIn multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could EPSS 0.4%