CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
668 vulnerabilities with CWE-693
CVE-2026-14050
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Password Policy Enforcement
CVSS 6.5
CVE-2026-14037
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via GPU Policy Bypass
CVSS 9.6
CVE-2026-14017
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via Navigation
CVSS 9.6
CVE-2026-13951
HIGH
Google Chrome < 150.0.7871.47 - Sandbox Escape via USB Policy Enforcement Bypass
CVSS 8.3
CVE-2026-13910
MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via WebXR Policy Enforcement
CVSS 6.5
CVE-2026-13909
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via DevTools Policy Bypass
CVSS 9.6
CVE-2026-13904
MEDIUM
Google Chrome < 150.0.7871.47 - Safe Browsing Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13886
MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Isolated Web Apps
CVSS 6.5
CVE-2026-13876
MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Malicious Network Traffic
CVSS 6.5
CVE-2026-13862
MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Web Authentication
CVSS 6.5
CVE-2026-13859
CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via ANGLE
CVSS 9.6
CVE-2026-13601
HIGH
Yelp yelp-xsl - Host File Disclosure via Flatpak OpenURI
CVSS 7.1
CVE-2026-58052
LOW
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
CVSS 3.3
CVE-2026-3472
LOW
Markdown image rendering bypass in AI bot tool result posts in Mattermost
CVSS 3.5
CVE-2026-55487
HIGH
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVSS 7.5
CVE-2026-53949
MEDIUM
Ghost Content API filter bypass reveals private fields
CVSS 5.3
CVE-2026-48721
HIGH
Warp: Env-var prefixes can lead to denylisted command autoexecution
CVSS 8.6
CVE-2026-57281
HIGH
Jenkins Script Security Plugin < 1402.v94c9ce464861 - Protection Mechanism Failure
CVSS 7.5
CVE-2026-57280
HIGH
Jenkins Script Security Plugin < 1402.v94c9ce464861 - Protection Mechanism Failure
CVSS 8.8
CVE-2026-54762
HIGH
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVSS 8.6
CVE-2026-54013
HIGH
Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI
CVSS 7.6
CVE-2026-49859
MEDIUM
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVSS 5.2
CVE-2026-44646
MEDIUM
LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
CVSS 5.3
CVE-2026-12457
MEDIUM
Google Chrome < 149.0.7827.155 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.2
CVE-2026-12438
HIGH
Google Chrome < 149.0.7827.155 - Sandbox Escape via WebView
CVSS 8.3
Details
Vulnerabilities
668