CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
669 vulnerabilities with CWE-693
CVE-2026-34072
HIGH
cronmaster: Middleware authentication bypass enabling unauthorized page access and server-action execution
CVSS 8.3
CVE-2026-5276
MEDIUM
Google Chrome <146.0.7680.178 - Info Disclosure
CVSS 6.5
CVE-2026-27893
HIGH
vLLM's hardcoded trust_remote_code=True in NemotronVL and KimiK25 bypasses user security opt-out
CVSS 8.8
CVE-2026-33622
HIGH
A PinchTab Security Policy Bypass in /wait Allows Arbitrary JavaScript Execution
CVSS 8.8
CVE-2026-33396
CRITICAL
OneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on Probe
CVSS 9.9
CVE-2026-20701
HIGH
macOS <14.8.5 - Privilege Escalation
CVSS 7.5
CVE-2026-20665
MEDIUM
Safari < 26.4 - Content Security Policy Bypass via Malicious Web Content
CVSS 6.5
CVE-2026-32947
MEDIUM
Egress Policy Bypass via DNS over HTTPS (DoH) in Harden-Runner (Community Tier)
CVSS 4.9
CVE-2026-32946
LOW
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
CVSS 2.7
CVE-2026-4447
HIGH
Google Chrome <146.0.7680.153 - RCE
CVSS 8.8
CVE-2026-28500
HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-21671
CRITICAL
Veeam Backup & Replication - Authenticated RCE
CVSS 9.1
CVE-2026-21669
CRITICAL
Veeam Backup & Replication 13.0.0.496-13.0.1 - Authenticated Remote Code Execution
CVSS 9.9
CVE-2026-21668
HIGH
Backup Repository - Privilege Escalation
CVSS 8.8
CVE-2026-3965
MEDIUM
Whyour Qinglong <=2.20.1 - Auth Bypass
CVSS 6.3
CVE-2026-0118
HIGH
Android - Local Privilege Escalation via oobconfig Logic Error
CVSS 8.4
CVE-2026-30938
MEDIUM
Parse Server <8.6.12/9.5.1-alpha.1 - Auth Bypass
CVSS 5.3
CVE-2026-22723
MEDIUM
Cloudfoundry UAA 77.30.0-78.7.0 - Auth Bypass
CVSS 6.5
CVE-2026-0017
HIGH
BiometricService.java - Privilege Escalation
CVSS 7.7
CVE-2026-0012
MEDIUM
ExpandableNotificationRow - Info Disclosure
CVSS 6.2
CVE-2026-0011
HIGH
Android Settings - Privilege Escalation
CVSS 8.4
CVE-2026-2803
HIGH
Firefox < 148.0 and Thunderbird < 148.0 - Information Disclosure via Settings UI Component
CVSS 7.5
CVE-2026-2768
CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Sandbox Escape via IndexedDB Storage
CVSS 10.0
CVE-2026-2761
CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Sandbox Escape in WebRender Component
CVSS 10.0
CVE-2026-26994
MEDIUM
uTLS <=1.6.7 - TLS Downgrade Vulnerability
CVSS 6.5
Details
Vulnerabilities
669