Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-53853HIGHOpenClaw < 2026.5.12 - Argument Pattern Bypass in Exec Allowlist via Linux and macOSEPSS 0.3%CVE-2022-4100MEDIUMWP Cerber Security <= 9.4 - IP Protection BypassEPSS 0.3%CVE-2025-14302HIGHGIGABYTE|Motherboard - Protection Mechanism FailureEPSS 0.3%CVE-2025-65100MEDIUMSecurity Snapshot May Use Unintended Timestamp When Only ISAR_APT_SNAPSHOT_DATE Is SetEPSS 0.3%CVE-2025-14303HIGHMSI|Motherboard - Protection Mechanism FailureEPSS 0.3%CVE-2024-45833MEDIUMMobile password gets saved in dictionary under conditionsEPSS 0.3%CVE-2026-14037CRITICALInsufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-52873MEDIUMStreambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electron RendererEPSS 0.3%CVE-2026-14120CRITICALInappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer EPSS 0.3%CVE-2025-12554MEDIUMMissing Security HeadersEPSS 0.3%CVE-2026-14017CRITICALInappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rendereEPSS 0.3%CVE-2026-13909CRITICALInsufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderEPSS 0.3%CVE-2026-92019HIGHMitigation bypass in the Remote Settings Client componentEPSS 0.3%CVE-2026-8958HIGHInformation disclosure, sandbox escape in the Security: Process Sandboxing componentEPSS 0.3%CVE-2025-6427CRITICALconnect-src Content Security Policy restriction could be bypassedEPSS 0.3%CVE-2026-55366CRITICALIn IP Multimedia Subsystem, there is a possible authentication bypass due to a logic error in the code. This could lead to remote escalationEPSS 0.3%CVE-2026-74959CRITICALMitigation bypass in the Storage: Cache API componentEPSS 0.3%CVE-2023-45372—An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.EPSS 0.3%CVE-2026-45770HIGHSuricata lua: excessive flow variable registration can bypass sandboxEPSS 0.3%CVE-2026-17779MEDIUMInappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass site isolation viEPSS 0.3%