CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

668 vulnerabilities with CWE-693
CVE-2026-46403 MEDIUM
Klever-Go KVM read-only execution can commit contract delete and upgrade side effects
CVSS 6.3
CVE-2026-56585 LOW
HCL IEM was affected with the Anti Clickjacking XFrame Options Header Missing
CVSS 3.1
CVE-2026-47392 CRITICAL
PraisonAI vulnerable to sandbox escape via `print.__self__` builtins module leak in `execute_code` (subprocess mode)
CVSS 9.9
CVE-2026-16407 CRITICAL
Mitigation bypass in the DOM: Service Workers component
CVSS 9.8
CVE-2026-16406 CRITICAL
Mozilla Firefox - Mitigation Bypass in the Networking Component
CVSS 9.1
CVE-2026-16394 CRITICAL
Mitigation bypass in the DOM: Security component
CVSS 9.1
CVE-2026-16390 CRITICAL
Mozilla Firefox - Mitigation Bypass in the Enterprise Policies Component
CVSS 9.1
CVE-2026-16388 CRITICAL
Sandbox escape in the DOM: Networking component
CVSS 9.8
CVE-2026-16383 CRITICAL
Mitigation bypass in the DOM: Networking component
CVSS 9.8
CVE-2026-16382 CRITICAL
Mitigation bypass in the DOM: Service Workers component
CVSS 9.8
CVE-2026-16380 CRITICAL
Mozilla Firefox - Mitigation Bypass in the Networking Component
CVSS 9.1
CVE-2026-16377 CRITICAL
Mozilla Firefox - Mitigation Bypass in the PDF Viewer Component
CVSS 9.8
CVE-2026-16370 CRITICAL
Mitigation bypass in the DOM: Networking component
CVSS 9.1
CVE-2026-16356 CRITICAL
Sandbox escape due to use-after-free in the Disability Access APIs component
CVSS 9.8
CVE-2026-44982 HIGH
CrowdSec AppSec silently drops request body for chunked / HTTP-2 requests
CVSS 7.2
CVE-2026-56087 MEDIUM
Dell ThinOS 10 < 2605_10.2100 - Protection Mechanism Failure
CVSS 6.1
CVE-2026-49981 HIGH
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
CVSS 8.2
CVE-2026-48808 HIGH
Twig: Sandbox property allowlist bypass via the `column` filter under `SourcePolicyInterface`
CVSS 7.5
CVE-2026-48807 CRITICAL
Twig: Sandbox `__toString()` policy bypass via `Traversable` in `join` and `replace` filters
CVSS 9.1
CVE-2026-48806 CRITICAL
Twig: Sandbox `__toString()` policy bypass via dynamic mapping keys
CVSS 9.1
CVE-2026-48805 CRITICAL
Twig: Sandbox state regression in deprecated internal wrappers in `src/Resources/core.php`
CVSS 9.1
CVE-2026-46639 MEDIUM
Twig: Sandbox property and method bypass via object-destructuring assignment
CVSS 6.5
CVE-2026-46638 HIGH
Twig < 3.26.0 - Sandbox SecurityPolicy Bypass via Cached Include
CVSS 8.1
CVE-2026-46634 CRITICAL
Twig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template name
CVSS 9.8
CVE-2026-49459 MEDIUM
DOMPurify: IN_PLACE mode preserves attributes of a clobbered root element, allowing XSS via attacker-controlled root DOM
CVSS 6.1
Details
Vulnerabilities 668