Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2025-13132HIGHDia: Increased Spoof Risk; Missing full screen toastEPSS 0.2%CVE-2025-62328LOWHCL Nomad server on Domino is affected by a missing default frame-ancestors directiveEPSS 0.2%CVE-2025-1940HIGHAndroid Intent confirmation prompt tapjacking using Select optionsEPSS 0.2%CVE-2026-59791LOWIn JetBrains YouTrack before 2026.2.17012 cSS injection via Mermaid diagram rendering was possibleEPSS 0.2%CVE-2026-87995HIGHOpen WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originEPSS 0.2%CVE-2026-74978HIGHClickjacking issue in the Widget componentEPSS 0.2%CVE-2025-6557MEDIUMInsufficient data validation in DevTools in Google Chrome on Windows prior to 138.0.7204.49 allowed a remote attacker who convinced a user tEPSS 0.2%CVE-2025-43854LOWDIFY vulnerable to Clickjacking AttackEPSS 0.2%CVE-2022-20214MEDIUMIn Car Settings app, the toggle button in Modify system settings is vulnerable to tapjacking attack. Attackers can overlay the toggle buttonEPSS 0.2%CVE-2024-10454MEDIUMClickjacking vulnerability in Clibo ManagerEPSS 0.2%CVE-2025-53096MEDIUMSunshine clickjacking in the UI leads to unauthorized actions being performedEPSS 0.2%CVE-2023-42011MEDIUMIBM Sterling B2B Integrator Standard Edition tapjackingEPSS 0.2%CVE-2026-10733MEDIUMImproper Restriction of Rendered UI Layers or Frames in GitLabEPSS 0.2%CVE-2025-36027MEDIUMIBM Datacap clickjackingEPSS 0.2%CVE-2023-0654LOWSpoofing User's Activity Loads in WARP Mobile Client (Android)EPSS 0.2%CVE-2025-28129MEDIUMPhpgurukul Hostel Management System 2.1 is vulnerable to clickjacking.EPSS 0.2%CVE-2026-27511MEDIUMTenda F3 Clickjacking in Web Management InterfaceEPSS 0.2%CVE-2026-24839MEDIUMDokploy has a clickjacking vulnerability - Missing X-Frame-Options and CSP frame-ancestors headersEPSS 0.2%CVE-2025-0421MEDIUMiFrame Injection in Mikrogrup's ShopsideEPSS 0.2%CVE-2026-12322MEDIUMClickjacking issue in the Widget: Gtk componentEPSS 0.2%