Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2025-50327HIGHAn issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypEPSS 0.7%CVE-2026-48546HIGHKanaDojo < 0.1.18 Sandbox Escape RCE via messages.cjsEPSS 0.7%CVE-2022-47544CRITICALAn issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.EPSS 0.7%CVE-2026-25056CRITICALn8n Arbitrary File Write leading to RCE in n8n Merge NodeEPSS 0.7%CVE-2023-0085MEDIUMMetform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection BypassEPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2024-38203MEDIUMWindows Package Library Manager Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43435MEDIUMJenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.7%CVE-2026-74895CRITICALopenssl_encrypt before 1.4.0 Plugin Sandbox Bypass via Process IsolationEPSS 0.7%CVE-2025-21384HIGHAzure Health Bot Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-76059HIGHLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.7%CVE-2025-21346HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2025-15039CRITICALAccount Takeover via Conditional Authentication Script Logic in Multiple WSO2 ProductsEPSS 0.7%CVE-2025-50324HIGHAn issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.EPSS 0.7%CVE-2025-50330HIGHAn issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via EPSS 0.7%CVE-2019-13516—In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection settinEPSS 0.7%CVE-2026-29649CRITICALNEMU contains an implementation flaw in its RISC-V Hypervisor CSR handling where henvcfg[7:4] (CBIE/CBCFE/CBZE-related fields) is incorrectlEPSS 0.7%CVE-2025-27665CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Antivirus Protection aEPSS 0.7%CVE-2023-30851LOWPotential HTTP policy bypass when using header rules in CiliumEPSS 0.7%CVE-2026-92948CRITICALvm2 3.9.6 through 3.11.5 Sandbox Escape via node:testEPSS 0.7%