Falhas do tipo CWE-1021

214 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2024-33377HIGHLB-LINK BL-W1210M v2.0 was discovered to contain a clickjacking vulnerability via the Administrator login page. Attackers can cause victim uEPSS 0.4%CVE-2026-44727CRITICALJupyter Server: Stored XSS in `NbconvertFileHandler` / `NbconvertPostHandler` via missing `sandbox` CSPEPSS 0.4%CVE-2022-3260MEDIUMThe response header has not enabled X-FRAME-OPTIONS, Which helps prevents against Clickjacking attack.. Some browsers would interpret these EPSS 0.4%CVE-2024-28196MEDIUMClickjacking in your_spotifyEPSS 0.4%CVE-2024-11695MEDIUMA crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoEPSS 0.4%CVE-2022-32517MEDIUMA CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface uEPSS 0.4%CVE-2026-40957MEDIUMFrameable content vulnerability in the Secure Access server login pageEPSS 0.4%CVE-2025-1018HIGHFullscreen notification is not displayed when fullscreen is re-requestedEPSS 0.4%CVE-2023-34658Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController.EPSS 0.4%CVE-2024-49796MEDIUMIBM ApplinX ClickjackingEPSS 0.4%CVE-2022-45417MEDIUMService Workers did not detect Private Browsing Mode correctly in all cases, which could have led to Service Workers being written to disk fEPSS 0.4%CVE-2021-3734MEDIUMImproper Restriction of Rendered UI Layers or Frames in yourls/yourlsEPSS 0.4%CVE-2023-3140MEDIUMKNIME Hub Web Application is vulnerable to clickjackingEPSS 0.4%CVE-2022-28649MEDIUMIn JetBrains YouTrack before 2022.1.43563 it was possible to include an iframe from a third-party domain in the issue descriptionEPSS 0.4%CVE-2025-6983MEDIUMClickjacking vulnerability on the management web application of TP-LINK Archer C1200EPSS 0.4%CVE-2023-2265MEDIUMImproper restriction of rendered UI layers or frames could lead to clickjacking attackEPSS 0.4%CVE-2024-10004CRITICALOpening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in tEPSS 0.4%CVE-2026-70486HIGHOpen WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originEPSS 0.4%CVE-2023-0780MEDIUMImproper Restriction of Rendered UI Layers or Frames in cockpit-hq/cockpitEPSS 0.4%CVE-2024-9397MEDIUMA missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjackingEPSS 0.4%