CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

668 vulnerabilities with CWE-693
CVE-2026-18015 CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via Crafted HTML Page in Tint Implementation
CVSS 9.6
CVE-2026-17943 MEDIUM
Google Chrome < 151.0.7922.72 - Content Security Policy Bypass via HTML Parser
CVSS 4.3
CVE-2026-17936 MEDIUM
Google Chrome < 151.0.7922.72 - Navigation Restriction Bypass via DevTools UI Gestures
CVSS 6.5
CVE-2026-17931 MEDIUM
Chrome < 151.0.7922.72 - Security Restriction Bypass via DevTools Inappropriate Implementation
CVSS 6.5
CVE-2026-17923 MEDIUM
Google Chrome <151.0.7922.72 - Unauth Nav Restriction Bypass via Crafted Domain in Enterprise Policy
CVSS 6.5
CVE-2026-17919 MEDIUM
Google Chrome - Privilege Escalation
CVSS 6.8
CVE-2026-17899 HIGH
Google Chrome - Privilege Escalation
CVSS 8.8
CVE-2026-17710 CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via MHTML Inappropriate Implementation on Mac
CVSS 9.6
CVE-2026-17695 CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via ANGLE Inappropriate Implementation on Mac
CVSS 9.6
CVE-2026-17677 HIGH
Google Chrome < 151.0.7922.72 on Android - Sandbox Escape via Crafted HTML Page in ANGLE
CVSS 8.8
CVE-2026-17676 CRITICAL
Google Chrome < 151.0.7922.72 - Sandbox Escape via ANGLE Inappropriate Implementation on Android
CVSS 9.6
CVE-2026-17669 CRITICAL
Google Chrome on iOS < 151.0.7922.72 - Sandbox Escape via Crafted HTML Page
CVSS 9.6
CVE-2026-17659 MEDIUM
Google Chrome < 151.0.7922.72 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.2
CVE-2026-67427 HIGH
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
CVSS 8.6
CVE-2026-64728 MEDIUM
Apple Safari - Denial of Service
CVSS 6.5
CVE-2026-64708 MEDIUM
macOS < 14.8.8, < 15.7.8, < 26.6 - Unauthenticated Gatekeeper Bypass via File Quarantine Check Evasion
CVSS 5.5
CVE-2026-28912 HIGH
macOS < 15.7.8 and < 26.6 - Privilege Escalation
CVSS 7.8
CVE-2026-28900 MEDIUM
macOS < 14.8.8, < 15.7.8 - Unprotected File Execution via Gatekeeper Bypass in Malicious ZIP Archive
CVSS 5.5
CVE-2026-28849 MEDIUM
macOS < 14.8.8 and < 15.7.8 - Gatekeeper Bypass via Maliciously Crafted ZIP Archive
CVSS 5.5
CVE-2026-66391 MEDIUM
Apache Wicket: leaked and missing CSP headers
CVSS 6.5
CVE-2026-48037 MEDIUM
Hulumi: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture
CVE-2026-48033 HIGH
Hulumi: Policy packs bypassed by a forged Pulumi-URN logical name
CVE-2026-65899 MEDIUM
DOMPurify before 3.4.9 Trusted Types Policy State Contamination
CVSS 6.1
CVE-2026-60166 LOW
Oracle Java SE 8u491 - Unauthenticated Information Disclosure via JavaFX Component
CVSS 3.1
CVE-2026-60164 LOW
Oracle Java SE 8u491 - Unauthenticated Information Disclosure via JavaFX in Sandboxed Applets
CVSS 3.1
Details
Vulnerabilities 668