CWE-693
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
669 vulnerabilities with CWE-693
CVE-2026-10174
MEDIUM
Aider-AI Aider Pre-commit Hook args.py protection mechanism
CVSS 6.3
CVE-2026-45697
CRITICAL
Formie: Pre-authenticated server-side template injection in Hidden fields
CVSS 9.8
CVE-2026-49325
MEDIUM
Indian Scout Bobber 2025 WCM voltage-based shutdown
CVSS 4.6
CVE-2026-49316
MEDIUM
Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
CVSS 4.6
CVE-2026-47676
MEDIUM
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
CVSS 5.3
CVE-2026-48792
MEDIUM
pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root execution
CVSS 4.4
CVE-2026-45102
CRITICAL
OneUptime: RCE due to Node.js' vm module escape via error objects and infinite recursion
CVSS 9.9
CVE-2026-44451
CRITICAL
Lumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass
CVSS 9.3
CVE-2026-44071
LOW
Netatalk 3.1.2-4.4.2 - Denial of Service via Missing FORTIFY_SOURCE Protection
CVSS 3.7
CVE-2026-9116
MEDIUM
Google Chrome < 148.0.7778.179 - Cross-Origin Data Leak via ServiceWorker Policy Bypass
CVSS 4.3
CVE-2026-9115
MEDIUM
Google Chrome < 148.0.7778.179 - Same Origin Policy Bypass via Service Worker
CVSS 4.3
CVE-2026-24425
HIGH
Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
CVSS 8.8
CVE-2026-8969
HIGH
Mitigation bypass in the DOM: Security component
CVSS 8.1
CVE-2026-8962
HIGH
Mitigation bypass in the DOM: Security component
CVSS 8.1
CVE-2026-8959
CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS 9.6
CVE-2026-8958
HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 8.6
CVE-2026-8945
HIGH
Sandbox escape in Firefox and Firefox Focus for Android
CVSS 7.5
CVE-2026-8585
HIGH
Google Chrome < 148.0.7778.168 on iOS - Out of Bounds Memory Read in Media
CVSS 7.5
CVE-2026-8583
MEDIUM
Google Chrome < 148.0.7778.168 - Insufficient Policy Enforcement in WebXR
CVSS 5.3
CVE-2026-8572
LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via Network Policy Enforcement
CVSS 3.1
CVE-2026-8571
HIGH
Google Chrome < 148.0.7778.168 - Sandbox Escape via GPU Policy Enforcement Bypass
CVSS 8.3
CVE-2026-8563
MEDIUM
Google Chrome < 148.0.7778.168 - Navigation Restriction Bypass via IFrame Sandbox Policy Enforcement
CVSS 4.3
CVE-2026-22707
MEDIUM
Strapi Upload Plugin MIME Validation Bypass via Content API
CVSS 5.4
CVE-2026-30904
LOW
Zoom Workplace < 7.0.0 - Authenticated Information Disclosure via Physical Access
CVSS 1.8
CVE-2026-44003
MEDIUM
vm2: Transformer Fast-Path Bypass Exposes Internal State Variable
CVSS 5.3
Details
Vulnerabilities
669