Falhas do tipo CWE-1021

215 resultados

Implementação inadequada de mecanismo de segurança

A lógica de segurança foi implementada de forma incompleta ou incorreta, deixando brechas que um atacante pode explorar. É quando o desenvolvedor tenta fazer o certo (validar entrada, criptografar dados, autenticar usuário), mas comete erros na execução que anulam a proteção.

Exemplo

Um sistema implementa autenticação de dois fatores, mas aceita o código OTP mesmo depois de expirado; ou valida se um arquivo é imagem checando apenas a extensão, não o conteúdo real do arquivo.

Como mitigar

Revise a implementação de controles de segurança críticos (autenticação, validação, criptografia) com code review rigoroso e testes de segurança específicos. Use bibliotecas consolidadas em vez de reinventar mecanismos; nunca implemente criptografia ou lógica sensível do zero sem expertise comprovada.

CVE-2025-14809HIGHAddress bar spoofing risk in ArcSearch on AndroidEPSS 0.2%CVE-2025-1923MEDIUMInappropriate implementation in Permission Prompts in Google Chrome prior to 134.0.6998.35 allowed an attacker who convinced a user to instaEPSS 0.2%CVE-2026-87538MEDIUMClickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveragEPSS 0.2%CVE-2024-56435MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-63522MEDIUMReverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management functionEPSS 0.2%CVE-2024-54112MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2025-52658LOWHCL MyXalytics is affected by the use of vulnerable/outdated versionsEPSS 0.2%CVE-2025-59849MEDIUMHCL BigFix Remote Control is vulnerable to an insecure CSP configurationEPSS 0.2%CVE-2025-59479MEDIUMCHOCO TEI WATCHER mini (IB-MCT001) contains an issue with improper restriction of rendered UI layers or frames. If a user clicks on content EPSS 0.2%CVE-2024-56436MEDIUMCross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service EPSS 0.2%CVE-2026-87655MEDIUMClickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elemenEPSS 0.2%CVE-2025-30191MEDIUMMalicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended actions or provide sensEPSS 0.2%CVE-2026-84139CRITICALClickjacking issue in the DOM: Events componentEPSS 0.2%CVE-2024-13066MEDIUMiFrame Injection in Akinsoft's LimonDeskEPSS 0.2%CVE-2026-70600LOWElectron: Cross-origin iframe can position native autofill popupEPSS 0.2%CVE-2025-36149MEDIUMIBM Concert Software clickjackingEPSS 0.2%CVE-2026-74980MEDIUMClickjacking issue in the Downloads component in Firefox for AndroidEPSS 0.2%CVE-2026-16397MEDIUMClickjacking issue in the WebExtensions component in Firefox for AndroidEPSS 0.2%CVE-2026-2378HIGHAddress bar spoofing risk in ArcSearch on AndroidEPSS 0.2%CVE-2025-58405MEDIUMLack of protection mechanisms against Clickjacking attacksEPSS 0.2%