CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

668 vulnerabilities with CWE-693
CVE-2026-14050 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via Password Policy Enforcement
CVSS 6.5
CVE-2026-14037 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via GPU Policy Bypass
CVSS 9.6
CVE-2026-14017 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via Navigation
CVSS 9.6
CVE-2026-13951 HIGH
Google Chrome < 150.0.7871.47 - Sandbox Escape via USB Policy Enforcement Bypass
CVSS 8.3
CVE-2026-13910 MEDIUM
Google Chrome < 150.0.7871.47 - Cross-Origin Data Leak via WebXR Policy Enforcement
CVSS 6.5
CVE-2026-13909 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via DevTools Policy Bypass
CVSS 9.6
CVE-2026-13904 MEDIUM
Google Chrome < 150.0.7871.47 - Safe Browsing Navigation Restriction Bypass via Crafted HTML Page
CVSS 6.5
CVE-2026-13886 MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Isolated Web Apps
CVSS 6.5
CVE-2026-13876 MEDIUM
Google Chrome < 150.0.7871.47 - Content Security Policy Bypass via Malicious Network Traffic
CVSS 6.5
CVE-2026-13862 MEDIUM
Google Chrome < 150.0.7871.47 - Insufficient Policy Enforcement in Web Authentication
CVSS 6.5
CVE-2026-13859 CRITICAL
Google Chrome < 150.0.7871.47 - Sandbox Escape via ANGLE
CVSS 9.6
CVE-2026-13601 HIGH
Yelp yelp-xsl - Host File Disclosure via Flatpak OpenURI
CVSS 7.1
CVE-2026-58052 LOW
7-Zip - Mark-of-the-Web Bypass via RAR5 Alternate Data Stream Name Collision
CVSS 3.3
CVE-2026-3472 LOW
Markdown image rendering bypass in AI bot tool result posts in Mattermost
CVSS 3.5
CVE-2026-55487 HIGH
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVSS 7.5
CVE-2026-53949 MEDIUM
Ghost Content API filter bypass reveals private fields
CVSS 5.3
CVE-2026-48721 HIGH
Warp: Env-var prefixes can lead to denylisted command autoexecution
CVSS 8.6
CVE-2026-57281 HIGH
Jenkins Script Security Plugin < 1402.v94c9ce464861 - Protection Mechanism Failure
CVSS 7.5
CVE-2026-57280 HIGH
Jenkins Script Security Plugin < 1402.v94c9ce464861 - Protection Mechanism Failure
CVSS 8.8
CVE-2026-54762 HIGH
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVSS 8.6
CVE-2026-54013 HIGH
Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI
CVSS 7.6
CVE-2026-49859 MEDIUM
Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVSS 5.2
CVE-2026-44646 MEDIUM
LiquidJS: `{% render %}` tag silently bypasses per-render `ownPropertyOnly:true` via `Context.spawn()`
CVSS 5.3
CVE-2026-12457 MEDIUM
Google Chrome < 149.0.7827.155 - Site Isolation Bypass via Crafted HTML Page
CVSS 4.2
CVE-2026-12438 HIGH
Google Chrome < 149.0.7827.155 - Sandbox Escape via WebView
CVSS 8.3
Details
Vulnerabilities 668