Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2025-64763LOWEnvoy forwards early CONNECT data in TCP proxy modeEPSS 0.3%CVE-2024-37182MEDIUMLack of permissions prompting when opening external URLsEPSS 0.3%CVE-2026-50545CRITICALFission Environment CRD PodSpec Injection Leading to Node Escape and Cluster TakeoverEPSS 0.3%CVE-2026-74957HIGHMitigation bypass in the Safe Browsing componentEPSS 0.3%CVE-2026-54013HIGHOpen WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUIEPSS 0.3%CVE-2026-69278HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-10950MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2026-10944MEDIUMInsufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin daEPSS 0.3%CVE-2023-0002MEDIUMCortex XDR Agent: Product Disruption by Local Windows UserEPSS 0.3%CVE-2025-44090HIGHAn issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%CVE-2026-79006MEDIUMProtection mechanism failure in HttpsUpgrades in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to bypass web origin policy EPSS 0.3%CVE-2024-6153HIGHParallels Desktop Updater Protection Mechanism Failure Software Downgrade VulnerabilityEPSS 0.3%CVE-2024-38874MEDIUMAn issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing access checks in the maEPSS 0.3%CVE-2026-8969HIGHMitigation bypass in the DOM: Security componentEPSS 0.3%CVE-2023-20573LOWDebug Exception Delivery in Secure Nested PagingEPSS 0.3%CVE-2026-53508MEDIUMoasdiff does not enforce --allow-external-refs=false on the git-revision load path (SSRF / local file read)EPSS 0.3%CVE-2025-44089HIGHAn issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.EPSS 0.3%CVE-2025-48534HIGHIn getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. ThisEPSS 0.3%CVE-2026-47209HIGHvm2: Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chainEPSS 0.3%CVE-2024-46976MEDIUMCircumvention of cross site scripting Protection in @backstage/plugin-techdocs-backendEPSS 0.3%