CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
668 vulnerabilities with CWE-693
CVE-2026-18015
CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via Crafted HTML Page in Tint Implementation
CVSS 9.6
CVE-2026-17943
MEDIUM
Google Chrome < 151.0.7922.72 - Content Security Policy Bypass via HTML Parser
CVSS 4.3
CVE-2026-17936
MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via DevTools UI Gestures
CVSS 6.5
CVE-2026-17931
MEDIUM
Chrome < 151.0.7922.72 - Security Restriction Bypass via DevTools Inappropriate Implementation
CVSS 6.5
CVE-2026-17923
MEDIUM
Google Chrome <151.0.7922.72 - Unauth Nav Restriction Bypass via Crafted Domain in Enterprise Policy
CVSS 6.5
CVE-2026-17919
MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.8
CVE-2026-17899
HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-17710
CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via MHTML Inappropriate Implementation on Mac
CVSS 9.6
CVE-2026-17695
CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via ANGLE Inappropriate Implementation on Mac
CVSS 9.6
CVE-2026-17677
HIGH
Google Chrome < 151.0.7922.72 on Android - Sandbox Escape via Crafted HTML Page in ANGLE
CVSS 8.8
CVE-2026-17676
CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via ANGLE Inappropriate Implementation on Android
CVSS 9.6
CVE-2026-17669
CRITICAL
Google Chrome on iOS < 151.0.7922.72 - Sandbox Escape via Crafted HTML Page
CVSS 9.6
CVE-2026-17659
MEDIUM
Google Chrome < 151.0.7922.72 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.2
CVE-2026-67427
HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVSS 8.6
CVE-2026-64728
MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-64708
MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unauthenticated Gatekeeper Bypass via File Quarantine Check Evasion
CVSS 5.5
CVE-2026-28912
HIGH
macOS < 15.7.8 and < 26.6 - Privilege Escalation
CVSS 7.8
CVE-2026-28900
MEDIUM
macOS < 14.8.8, < 15.7.8 - Unprotected File Execution via Gatekeeper Bypass in Malicious ZIP Archive
CVSS 5.5
CVE-2026-28849
MEDIUM
macOS < 14.8.8 and < 15.7.8 - Gatekeeper Bypass via Maliciously Crafted ZIP Archive
CVSS 5.5
CVE-2026-66391
MEDIUM
Apache Wicket: leaked and missing CSP headers
CVSS 6.5
CVE-2026-48037
MEDIUM
Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
CVE-2026-48033
HIGH
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
CVE-2026-65899
MEDIUM
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
CVSS 6.1
CVE-2026-60166
LOW
Oracle Java SE 8u491 - Unauthenticated Information Disclosure via JavaFX Component
CVSS 3.1
CVE-2026-60164
LOW
Oracle Java SE 8u491 - Unauthenticated Information Disclosure via JavaFX in Sandboxed Applets
CVSS 3.1
Details
Vulnerabilities
668