Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2025-59950MEDIUMFreshRSS: Double clickjacking can lead to privilege escalationEPSS 0.3%CVE-2025-52987MEDIUMParagon Automation: A clickjacking vulnerability in the web server configuration has been addressedEPSS 0.3%CVE-2024-54110MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.3%CVE-2025-57769MEDIUMFressRSS: Clickjacking can lead to XSS and/or privilege escalationEPSS 0.3%CVE-2024-7523MEDIUMA select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. EPSS 0.3%CVE-2025-14373MEDIUMInappropriate implementation in Toolbar in Google Chrome on Android prior to 143.0.7499.110 allowed a remote attacker to perform domain spooEPSS 0.3%CVE-2023-47774MEDIUMWordPress Jetpack plugin < 12.7 - Auth. Iframe Injection vulnerabilityEPSS 0.3%CVE-2026-38979MEDIUMajenti through v2.2.13 has a clickjacking weakness in the browser-facing login and administrative UI. In ajenti-core/aj/http.py, the core HTEPSS 0.3%CVE-2025-14812HIGHAddress bar spoofing risk in Arc Search on iOSEPSS 0.3%CVE-2025-5267MEDIUMClickjacking vulnerability could have led to leaking saved payment card detailsEPSS 0.3%CVE-2026-9396MEDIUMBesen BS20 EV Charging Station Firmware Version Check ui layerEPSS 0.3%CVE-2021-29827MEDIUMIBM InfoSphere Information Server clickjackingEPSS 0.3%CVE-2026-74958HIGHInformation disclosure in the WebRTC componentEPSS 0.3%CVE-2025-6434MEDIUMHTTPS-Only exception screen lacked anti-clickjacking delayEPSS 0.3%CVE-2025-31138MEDIUMtarteaucitron.js allows UI manipulation via unrestricted CSS injectionEPSS 0.3%CVE-2025-54527MEDIUMIn JetBrains YouTrack before 2025.2.86935, 2025.2.87167, 2025.3.87341, 2025.3.87344 improper iframe configuration in widget sandbox allowEPSS 0.3%CVE-2025-7903MEDIUMyangzongzhuan RuoYi Image Source ui layerEPSS 0.3%CVE-2023-6093MEDIUMOnCell G3150A-LTE Series: Clickjacking VulnerabilityEPSS 0.3%CVE-2025-0546MEDIUMXSS in Mevzuattr Software's MevzuatTREPSS 0.3%CVE-2023-7013MEDIUMInappropriate implementation in Compositing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially spoof securityEPSS 0.2%