Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2025-24874MEDIUMMissing Defense in Depth Against Clickjacking in SAP Commerce BackofficeEPSS 0.3%CVE-2023-45698MEDIUMHCL Sametime is impacted by clickjackingEPSS 0.3%CVE-2025-9108MEDIUMPortabilis i-Diario Login Page ui layerEPSS 0.3%CVE-2024-55888HIGHContent Security Policy appears to be missing in software and production setupEPSS 0.3%CVE-2025-54139MEDIUMHAX CMS' application pages are vulnerable to clickjackingEPSS 0.3%CVE-2026-18534HIGHAddress bar spoofing risk in affected iOS versions of Arc SearchEPSS 0.3%CVE-2025-25213MEDIUMImproper restriction of rendered UI layers or frames issue exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If a user views and clicks on the cEPSS 0.3%CVE-2026-23731MEDIUMWeGIA Clickjacking VulnerabilityEPSS 0.3%CVE-2026-70486HIGHOpen WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcoding allow-same-originEPSS 0.3%CVE-2025-32385MEDIUMEspoCRM allows unrestricted Embedding in Iframe dashletEPSS 0.3%CVE-2024-53976MEDIUMUnder certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what tEPSS 0.3%CVE-2025-15032HIGHCVE-2025-15032: Increased Spoofing risk; custom new window missing about:blankEPSS 0.3%CVE-2025-27455MEDIUMCVE-2025-27455EPSS 0.3%CVE-2025-0362MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.3%CVE-2026-28971MEDIUMThe issue was addressed with improved UI handling. This issue is fixed in Safari 26.5, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, visionOS EPSS 0.3%CVE-2024-6466MEDIUMNEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FEPSS 0.3%CVE-2025-1494MEDIUMIBM Cognos Command Center clickjackingEPSS 0.3%CVE-2024-0669MEDIUMCross-Frame Scripting (XFS) on Plone CMSEPSS 0.3%CVE-2026-26000MEDIUMXWiki Platform affected by click-jacking through CSS injection in commentsEPSS 0.3%CVE-2026-12348HIGHAddress Bar Spoofing in Arc Search for Android (window.open race condition)EPSS 0.3%