Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2026-79919MEDIUMMaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)EPSS 0.4%CVE-2025-71322HIGHPickleScan - Unsafe Globals Check Bypass via pty.spawn FunctionEPSS 0.4%CVE-2025-60711MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-59223MEDIUMOpen WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matchingEPSS 0.4%CVE-2026-43670HIGHA Content Security Policy bypass was addressed with improved enforcement in AudioWorklet contexts. This issue is fixed in Safari 26.5, iOS 1EPSS 0.4%CVE-2023-27383MEDIUMProtection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a pEPSS 0.4%CVE-2026-26994MEDIUMuTLS ServerHellos are accepted without checking TLS 1.3 downgrade canariesEPSS 0.4%CVE-2026-14625MEDIUMNousResearch hermes-agent server.py shell.exec protection mechanismEPSS 0.4%CVE-2018-11459—A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2018-11460—A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versEPSS 0.4%CVE-2026-16382CRITICALMitigation bypass in the DOM: Service Workers componentEPSS 0.4%CVE-2025-48626HIGHIn multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could EPSS 0.4%CVE-2026-16388CRITICALSandbox escape in the DOM: Networking componentEPSS 0.4%CVE-2023-32644MEDIUMProtection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.240 may allow an unaEPSS 0.4%CVE-2025-47159HIGHWindows Virtualization-Based Security (VBS) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-64728MEDIUMA permissions issue was addressed with improved validation. This issue is fixed in Safari 26.6, iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, EPSS 0.4%CVE-2026-44982HIGHCrowdSec AppSec silently drops request body for chunked / HTTP-2 requestsEPSS 0.4%CVE-2026-48807HIGHTwig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filtersEPSS 0.4%CVE-2019-13535MEDIUMMedtronic Valleylab FT10 and LS10 Protection Mechanism FailureEPSS 0.4%CVE-2026-49459MEDIUMDOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOMEPSS 0.4%