Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2026-22753HIGHServlet Path Not Correctly Included in Path Matching of HttpSecurity#securityMatchersEPSS 0.2%CVE-2026-44003MEDIUMvm2: Transformer Fast-Path Bypass Exposes Internal State VariableEPSS 0.2%CVE-2026-12302MEDIUMMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2023-22655MEDIUMProtection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a EPSS 0.2%CVE-2026-92030MEDIUMMitigation bypass in the DOM: Copy & Paste and Drag & Drop componentEPSS 0.2%CVE-2026-12316CRITICALMitigation bypass in the DOM: Security componentEPSS 0.2%CVE-2026-70601HIGHElectron: Context isolation bypass via Function.prototype.bind hijackEPSS 0.2%CVE-2026-13342MEDIUMSecurity Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_passwordEPSS 0.2%CVE-2026-73288MEDIUMRustFS: Object Lock (WORM) protections are treated as absent when bucket metadata cannot be read, allowing retained objects to be deletedEPSS 0.2%CVE-2026-11282CRITICALInsufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially performEPSS 0.2%CVE-2025-22429CRITICALIn multiple locations, there is a possible way to execute arbitrary code due to a logic error in the code. This could lead to local escalatiEPSS 0.2%CVE-2025-67485MEDIUMHTTP/HTTPS Traffic Interception Bypass in mad-proxyEPSS 0.2%CVE-2026-11248HIGHInappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictiEPSS 0.2%CVE-2024-6832MEDIUMAccount Lockout Failure via Secondary User Store Inaccessibility in Multiple WSO2 Products Allows Brute Force AttacksEPSS 0.2%CVE-2026-40158HIGHPraisonAI has Improper Control of Generation of Code ('Code Injection') and Protection Mechanism Failure in praisonaiEPSS 0.2%CVE-2026-5276MEDIUMInsufficient policy enforcement in WebUSB in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to obtain potentially sensitiveEPSS 0.2%CVE-2025-59033HIGHThe Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only tEPSS 0.2%CVE-2026-11170HIGHInappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level prEPSS 0.2%CVE-2026-7978HIGHInappropriate implementation in Companion in Google Chrome on Mac prior to 148.0.7778.96 allowed a remote attacker to perform OS-level priviEPSS 0.2%CVE-2026-42261HIGHPromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`EPSS 0.2%