Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2025-9866HIGHInappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security poliEPSS 0.4%CVE-2026-12294CRITICALSandbox escape in the DOM: Workers componentEPSS 0.4%CVE-2026-49981MEDIUMTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`EPSS 0.4%CVE-2026-79918MEDIUMMaxKB: Sandbox escape via unhooked fexecveEPSS 0.4%CVE-2026-14409HIGHInappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in speciEPSS 0.4%CVE-2024-20438MEDIUMCisco Nexus Dashboard Fabric Controller Unauthorized REST API VulnerabilityEPSS 0.4%CVE-2022-48287HIGHThe HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data integrity.EPSS 0.4%CVE-2026-60086MEDIUMPraisonAI before 4.6.78 Prompt Injection Defense BypassEPSS 0.4%CVE-2026-52873MEDIUMStreambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electron RendererEPSS 0.4%CVE-2024-55024HIGHAn authentication bypass vulnerability in the authorization mechanism of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorizEPSS 0.4%CVE-2026-53949MEDIUMGhost Content API filter bypass reveals private fieldsEPSS 0.4%CVE-2025-55886MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment hisEPSS 0.4%CVE-2026-0881CRITICALSandbox escape in the Messaging System componentEPSS 0.4%CVE-2026-48575HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-47656HIGHWindows Boot Manager Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-48570HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-48568HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2025-10528HIGHSandbox escape due to undefined behavior, invalid pointer in the Graphics: Canvas2D componentEPSS 0.4%CVE-2026-45588HIGHSecure Boot Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2026-44003MEDIUMvm2: Transformer Fast-Path Bypass Exposes Internal State VariableEPSS 0.4%