Weaknesses of type CWE-693

664 results

Falha no Mecanismo de Proteção

É uma fraqueza genérica que abrange falhas em controles de segurança implementados para proteger o software—como validação, autenticação, criptografia ou controle de acesso—que não funcionam corretamente ou podem ser contornados. Quando esses mecanismos falham, o software fica exposto a ataques que deveriam ser prevenidos.

Example

Um sistema implementa CORS para restringir requisições cross-origin, mas a configuração está errada (aceita qualquer origem), permitindo que um atacante roube dados sensíveis via JavaScript malicioso executado em outro site. Ou um login exige senha forte, mas o algoritmo de hashing usado é fraco (MD5), permitindo força bruta rápida.

How to mitigate

Valide e teste rigorosamente cada mecanismo de proteção (autenticação, autorização, validação de entrada, criptografia) em cenários de ataque reais. Não confie em defaults de bibliotecas—revise configurações de segurança, use bibliotecas criptográficas consolidadas, implemente rate limiting, e mantenha logs e alertas para detectar tentativas de contorno.

CVE-2013-2465CRITICALUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlierEPSS 98.7%KEVCVE-2024-21412HIGHInternet Shortcut Files Security Feature Bypass VulnerabilityEPSS 95.4%KEVCVE-2013-0431MEDIUMUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-EPSS 90.0%KEVCVE-2019-1003030CRITICALA sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/woEPSS 75.6%KEVCVE-2025-40536HIGHSolarWinds Web Help Desk Security Control Bypass VulnerabilityEPSS 71.5%KEVCVE-2025-0411HIGH7-Zip Mark-of-the-Web Bypass VulnerabilityEPSS 67.1%KEVCVE-2026-32202MEDIUMWindows Shell Spoofing VulnerabilityEPSS 63.7%KEVCVE-2024-34144CRITICALA sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allowsEPSS 48.1%CVE-2024-29988HIGHSmartScreen Prompt Security Feature Bypass VulnerabilityEPSS 45.2%KEVCVE-2018-20251In WinRAR versions prior to and including 5.61, there is path traversal vulnerability when crafting the filename field of the ACE format. ThEPSS 31.5%CVE-2024-29510MEDIUMArtifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with a uniprint device.EPSS 28.0%CVE-2026-21510HIGHWindows Shell Security Feature Bypass VulnerabilityEPSS 25.8%KEVCVE-2024-31142HIGHx86: Incorrect logic for BTC/SRSO mitigationsEPSS 17.4%CVE-2026-21513HIGHMSHTML Framework Security Feature Bypass VulnerabilityEPSS 15.4%KEVCVE-2025-47984HIGHWindows GDI Information Disclosure VulnerabilityEPSS 14.3%CVE-2024-38213MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 13.6%KEVCVE-2025-68668CRITICALn8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code NodeEPSS 12.9%CVE-2024-30050MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 11.5%CVE-2024-38217MEDIUMWindows Mark of the Web Security Feature Bypass VulnerabilityEPSS 9.8%KEVCVE-2021-35556MEDIUMVulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are afEPSS 7.9%