Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-8401CRITICALSandbox escape in the Profile Backup componentEPSS 0.3%CVE-2026-73217HIGHCursor: Sandbox escape via tampered Python virtual environmentsEPSS 0.3%CVE-2025-49193MEDIUMMissing HTTP Security HeadersEPSS 0.3%CVE-2023-51748HIGHScaleFusion 10.5.2 does not properly limit users to the Edge application because Ctrl-O and Ctrl-S can be used. This is fixed in 10.5.7 by pEPSS 0.3%CVE-2026-16370CRITICALMitigation bypass in the DOM: Networking componentEPSS 0.3%CVE-2026-16380CRITICALMitigation bypass in the Networking componentEPSS 0.3%CVE-2026-57135HIGHPraisonAI SandboxExecutor network-isolated mode does not block non-proxy-aware network clientsEPSS 0.3%CVE-2024-39599MEDIUM[CVE-2024-39599] Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP PlatformEPSS 0.3%CVE-2026-13859CRITICALInappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escEPSS 0.3%CVE-2025-0276MEDIUMHCL BigFix Modern Client Management (MCM) is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2026-32947MEDIUMEgress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)EPSS 0.3%CVE-2026-77892MEDIUMWindows Boot Manager Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2025-0277MEDIUMHCL BigFix Mobile is affected by an insecure Content Security Policy (CSP)EPSS 0.3%CVE-2026-13951HIGHInsufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer prEPSS 0.3%CVE-2026-47656HIGHWindows Boot Manager Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48568HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-45588HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48570HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-48575HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2025-64763LOWEnvoy forwards early CONNECT data in TCP proxy modeEPSS 0.3%