Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2025-49139MEDIUM@haxtheweb/haxcms-nodejs Iframe Phishing vulnerabilityEPSS 0.4%CVE-2024-30109LOWLack of Clickjacking Protection vulnerability affects DRYiCE AEX v10EPSS 0.4%CVE-2025-1019MEDIUMFullscreen notification not properly displayedEPSS 0.4%CVE-2024-8388MEDIUMMultiple prompts and panels from both Firefox and the Android OS could be used to obscure the notification announcing the transition to fullEPSS 0.4%CVE-2025-64387MEDIUMCLICKJACKINGEPSS 0.4%CVE-2024-2383MEDIUMClickjacking Vulnerability in zenml-io/zenmlEPSS 0.4%CVE-2024-57369MEDIUMClickjacking vulnerability in typecho v1.2.1.EPSS 0.4%CVE-2023-36920MEDIUMClickjacking vulnerability in SAP Enable NowEPSS 0.4%CVE-2023-28159MEDIUMThe fullscreen notification could have been hidden on Firefox for Android by using download popups, resulting in potential user confusion orEPSS 0.3%CVE-2023-25748MEDIUMBy displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion orEPSS 0.3%CVE-2025-49191MEDIUMDashboards and iFrames can link malicious web contentEPSS 0.3%CVE-2025-41000LOWCross-Frame Scripting (XFS) in BoomCMSEPSS 0.3%CVE-2024-39320MEDIUMDiscourse allows iframe injection though default site settingEPSS 0.3%CVE-2025-24310MEDIUMImproper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attEPSS 0.3%CVE-2025-1917MEDIUMInappropriate implementation in Browser UI in Google Chrome on Android prior to 134.0.6998.35 allowed a remote attacker to perform UI spoofiEPSS 0.3%CVE-2026-60370HIGHVulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). SupporEPSS 0.3%CVE-2025-49192MEDIUMClickjackingEPSS 0.3%CVE-2026-37470HIGHAn issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTEPSS 0.3%CVE-2026-22918MEDIUMAn attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously craEPSS 0.3%CVE-2026-70608HIGHElectron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation pathEPSS 0.3%