CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
668 vulnerabilities with CWE-693
CVE-2026-49458
MEDIUM
DOMPurify: Cross-realm IN_PLACE sanitization leaves executable markup intact via realm-bound `instanceof` checks
CVSS 6.1
CVE-2026-50646
HIGH
Microsoft .NET Framework, .NET, and Visual Studio - Local Code Execution
CVSS 7.8
CVE-2026-47305
HIGH
Visual Studio Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-50661
MEDIUM
Microsoft Windows 10 Version 1607 - Windows BitLocker Security Feature Bypass Vulnerability
CVSS 6.1
CVE-2026-34348
MEDIUM
Microsoft Windows 10 Version 1809 - Windows Event Logging Service Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-15618
MEDIUM
mosaxiv clawlet exec Safety Guard tool_exec.go guardExecCommand protection mechanism
CVSS 6.3
CVE-2026-15528
LOW
lamaalrajih kicad-mcp path_validator.py protection mechanism
CVSS 3.3
CVE-2026-61437
HIGH
PraisonAI before 1.6.78 Remote Code Execution via tools.py
CVSS 7.8
CVE-2026-60086
MEDIUM
PraisonAI before 4.6.78 Prompt Injection Defense Bypass
CVSS 5.3
CVE-2026-59854
MEDIUM
SiYuan: Incomplete IsSensitivePath denylist: globalCopyFiles reads home-dir credential dotfiles into the workspace
CVSS 4.9
CVE-2026-0278
HIGH
Prisma Access Agent: Multiple DLP Policy Bypass Vulnerabilities on Windows
CVSS 7.8
CVE-2026-59223
MEDIUM
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVSS 4.3
CVE-2026-59207
MEDIUM
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
CVSS 6.5
CVE-2026-14535
HIGH
Fickling MLAllowlist analysis pass rendered inoperative by shared mutable state in AnalysisContext.shorten_code()
CVSS 8.8
CVE-2026-14625
MEDIUM
NousResearch hermes-agent server.py shell.exec protection mechanism
CVSS 6.3
CVE-2026-14440
MEDIUM
Cloudflare Universal SSL automatically managed CAA RRset supersedes customer-configured CAA records
CVSS 6.8
CVE-2026-14409
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 7.5
CVE-2026-14151
HIGH
Google Chrome < 150.0.7871.47 - Sandbox Escape via Crafted HTML Page
CVSS 8.3
CVE-2026-14120
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via DevTools
CVSS 9.6
CVE-2026-14101
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via Crafted HTML Page
CVSS 9.6
CVE-2026-14097
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via WebAppInstalls
CVSS 9.6
CVE-2026-14092
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Malicious Network Traffic
CVSS 4.3
CVE-2026-14076
MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Crafted HTML Page
CVSS 4.3
CVE-2026-14059
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Related-Website-Sets Policy Enforcement
CVSS 6.5
CVE-2026-14058
MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Parser
CVSS 4.3
Details
Vulnerabilities
668