Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-16388CRITICALSandbox escape in the DOM: Networking componentEPSS 0.4%CVE-2025-47159HIGHWindows Virtualization-Based Security (VBS) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2023-32644MEDIUMProtection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unaEPSS 0.4%CVE-2026-64728MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, EPSS 0.4%CVE-2026-8962HIGHMitigation bypass in the DOM: Security componentEPSS 0.4%CVE-2026-44982HIGHCrowdSec AppSec silently drops request body for chunked / HTTP-2 requestsEPSS 0.4%CVE-2026-45459LOWMicrosoft Excel Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-8945HIGHSandbox escape in Firefox and Firefox Focus for AndroidEPSS 0.4%CVE-2026-77401MEDIUMZope AccessControl: Information disclosure through Python string `format` and `format_map` functionsEPSS 0.4%CVE-2026-48807HIGHTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filtersEPSS 0.4%CVE-2019-13535MEDIUMMedtronic Valleylab FT10 and LS10 Protection Mechanism FailureEPSS 0.4%CVE-2026-2768CRITICALSandbox escape in the Storage: IndexedDB componentEPSS 0.4%CVE-2026-49459MEDIUMDOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOMEPSS 0.4%CVE-2025-9866HIGHInappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security poliEPSS 0.4%CVE-2026-12294CRITICALSandbox escape in the DOM: Workers componentEPSS 0.4%CVE-2025-50330HIGHAn issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via EPSS 0.4%CVE-2025-50324HIGHAn issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.EPSS 0.4%CVE-2024-20438MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.4%CVE-2022-48287HIGHThe HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.EPSS 0.4%CVE-2026-49981MEDIUMTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`EPSS 0.4%