CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
669 vulnerabilities with CWE-693
CVE-2026-20667
HIGH
iPadOS < 26.3 - Sandbox Escape via Logic Issue
CVSS 8.8
CVE-2026-21513
HIGH
KEV
Windows MSHTML Security Feature Bypass (10, 11, 23H2, 24H2)
CVSS 8.8
CVE-2026-21510
HIGH
KEV
Microsoft Windows Shell - Protection Mechanism Failure
CVSS 8.8
CVE-2026-25115
CRITICAL
n8n < 2.4.8 - Authenticated Remote Code Execution via Python Code Node Sandbox Escape
CVSS 9.9
CVE-2026-25056
HIGH
n8n < 1.118.0 - Authenticated Arbitrary File Write and Remote Code Execution via Merge Node SQL Query Mode
CVSS 8.8
CVE-2026-0620
MEDIUM
TP-Link AXE75 < 1.5.1 Build 20251202 - VPN Encryption Bypass via L2TP Without IPSec
CVE-2026-1232
MEDIUM
BeyondTrust Privilege Management <25.7 - Privilege Escalation
CVE-2026-23553
LOW
Xen >=4.6.0 - Improper Branch Target Buffer Isolation via IBPB Skip
CVSS 2.9
CVE-2026-23830
CRITICAL
sandboxjs < 0.8.26 - Remote Code Execution via AsyncFunction Constructor Access
CVSS 10.0
CVE-2026-24868
MEDIUM
Firefox < 147.0.2 - Privilege Escalation
CVSS 6.5
CVE-2026-22709
CRITICAL
NPM Vm2 < 3.10.2 - Code Injection
CVSS 9.8
CVE-2026-22686
CRITICAL
enclave-vm < 2.7.0 - Sandbox Escape via Host Error Prototype Chain Traversal
CVSS 10.0
CVE-2026-20824
MEDIUM
Microsoft Windows Remote Assistance - Protection Mechanism Failure
CVSS 5.5
CVE-2026-0881
CRITICAL
Firefox and Thunderbird < 147.0 - Sandbox Escape via Messaging System Component
CVSS 10.0
CVE-2026-0877
HIGH
Firefox <147- Thunderbird <140.7 - Mitigation Bypass
CVSS 8.1
CVE-2025-50330
HIGH
ZipGenius <= 6.3.2.3116 - Remote Code Execution via zipgenius.exe
CVSS 8.8
CVE-2025-50329
CRITICAL
PowerArchiver <= 22.00.11 - Remote Code Execution via powerarc.exe
CVSS 9.8
CVE-2025-50327
HIGH
ZPAQFRANZ <= 61.3 - Remote Code Execution via Mark-of-the-Web Protection Bypass
CVSS 8.8
CVE-2025-50325
MEDIUM
BandiZip 7.37 - Unauthenticated Mark-of-the-Web Protection Bypass
CVSS 5.4
CVE-2025-50324
HIGH
OneCommander 3.96.0.0 - Remote Code Execution via OneCommander.exe Component
CVSS 8.8
CVE-2025-44090
HIGH
CoffeeZip 4.8.0.0 - Remote Code Execution via Crafted Archive File Download and Execution
CVSS 8.8
CVE-2025-44089
HIGH
NCH Software ExpressZip 11.29 - Arbitrary Code Execution via Crafted Archive File
CVSS 8.8
CVE-2025-71373
HIGH
picklescan - Remote Code Execution via operator.methodcaller Detection Bypass
CVSS 8.1
CVE-2025-71352
HIGH
picklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle Files
CVSS 8.1
CVE-2025-71322
HIGH
PickleScan - Unsafe Globals Check Bypass via pty.spawn Function
CVSS 8.8
Details
Vulnerabilities
669