Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-92778MEDIUMCMAK through 3.0.0.6 Feature Gate Bypass via HTML Form RoutesEPSS 0.3%CVE-2026-74938CRITICALMitigation bypass in the JavaScript: GC componentEPSS 0.3%CVE-2020-3458MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000/2100 Series Appliances Secure Boot Bypass VulnerabilitiesEPSS 0.3%CVE-2026-17659MEDIUMInappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rendEPSS 0.3%CVE-2026-45656HIGHUEFI Secure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-92066CRITICALSandbox escape in the Profile Backup componentEPSS 0.3%CVE-2026-14097CRITICALInappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised EPSS 0.3%CVE-2026-14050MEDIUMInsufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data viaEPSS 0.3%CVE-2026-13910MEDIUMInsufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin dEPSS 0.3%CVE-2026-14059MEDIUMInsufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origEPSS 0.3%CVE-2026-39452MEDIUMProtection mechanism failure for some Intel(R) Transfer Learning Tool before version v0.7 within Ring 3: User Applications may allow an escaEPSS 0.3%CVE-2026-28500HIGHONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain AttackEPSS 0.3%CVE-2026-57120MEDIUMPraisonAI: execute_code sandbox bypass: str.format C-level attribute access reads every blocklisted dunderEPSS 0.3%CVE-2025-12094MEDIUMOOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) <= 1.2.53 - Unauthenticated IP Header SpoofingEPSS 0.3%CVE-2019-19278—A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 Drives MLFB 6SR32..-.....-.... MLFB 6SR4...-.....-.... MLFB 6SR5...-..EPSS 0.3%CVE-2026-76827MEDIUMSearch-indexer: search-indexer: update/delete operations not scoped to caller's cluster (cross-tenant data tampering)EPSS 0.3%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.3%CVE-2025-52951MEDIUMJunos OS: IPv6 firewall filter fails to match payload-protocolEPSS 0.3%CVE-2026-16390CRITICALMitigation bypass in the Enterprise Policies componentEPSS 0.3%CVE-2026-84809HIGHTencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python BytecodeEPSS 0.3%