CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

550 vulnerabilities with CWE-693
CVE-2026-32946 LOW
Egress Policy Bypass via DNS over TCP in Harden-Runner (Community Tier)
CVSS 2.7
CVE-2026-4447 HIGH
Google Chrome <146.0.7680.153 - RCE
CVSS 8.8
CVE-2026-28500 HIGH
ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack
CVSS 8.6
CVE-2026-21671 CRITICAL
Veeam Backup & Replication - Authenticated RCE
CVSS 9.1
CVE-2026-21669 CRITICAL
Veeam Backup & Replication 13.0.0.496-13.0.1 - Authenticated Remote Code Execution
CVSS 9.9
CVE-2026-21668 HIGH
Backup Repository - Privilege Escalation
CVSS 8.8
CVE-2026-3965 MEDIUM
Whyour Qinglong <=2.20.1 - Auth Bypass
CVSS 6.3
CVE-2026-0118 HIGH
Android - Local Privilege Escalation via oobconfig Logic Error
CVSS 8.4
CVE-2026-30938 MEDIUM
Parse Server <8.6.12/9.5.1-alpha.1 - Auth Bypass
CVSS 5.3
CVE-2026-22723 MEDIUM
Cloudfoundry UAA 77.30.0-78.7.0 - Auth Bypass
CVSS 6.5
CVE-2026-0017 HIGH
BiometricService.java - Privilege Escalation
CVSS 7.7
CVE-2026-0012 MEDIUM
ExpandableNotificationRow - Info Disclosure
CVSS 6.2
CVE-2026-0011 HIGH
Android Settings - Privilege Escalation
CVSS 8.4
CVE-2026-2803 HIGH
Firefox < 148.0 and Thunderbird < 148.0 - Information Disclosure via Settings UI Component
CVSS 7.5
CVE-2026-2768 CRITICAL
Firefox < 148 and Firefox ESR < 140.8 - Sandbox Escape via IndexedDB Storage
CVSS 10.0
CVE-2026-2761 CRITICAL
Firefox < 115.33.0, < 148.0 and Thunderbird < 140.8.0, < 148.0 - Sandbox Escape in WebRender Component
CVSS 10.0
CVE-2026-26994 MEDIUM
uTLS <=1.6.7 - TLS Downgrade Vulnerability
CVSS 6.5
CVE-2026-20667 HIGH
iPadOS < 26.3 - Sandbox Escape via Logic Issue
CVSS 8.8
CVE-2026-21513 HIGH KEV
Windows MSHTML Security Feature Bypass (10, 11, 23H2, 24H2)
CVSS 8.8
CVE-2026-21510 HIGH KEV
Microsoft Windows Shell - Protection Mechanism Failure
CVSS 8.8
CVE-2026-25115 CRITICAL
n8n < 2.4.8 - Authenticated Remote Code Execution via Python Code Node Sandbox Escape
CVSS 9.9
CVE-2026-25056 HIGH
n8n < 1.118.0 - Authenticated Arbitrary File Write and Remote Code Execution via Merge Node SQL Query Mode
CVSS 8.8
CVE-2026-0620 MEDIUM
TP-Link AXE75 < 1.5.1 Build 20251202 - VPN Encryption Bypass via L2TP Without IPSec
CVE-2026-1232 MEDIUM
BeyondTrust Privilege Management <25.7 - Privilege Escalation
CVE-2026-23553 LOW
Xen >=4.6.0 - Improper Branch Target Buffer Isolation via IBPB Skip
CVSS 2.9
Details
Vulnerabilities 550