CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

669 vulnerabilities with CWE-693
CVE-2026-10174 MEDIUM
Aider-AI Aider Pre-commit Hook args.py protection mechanism
CVSS 6.3
CVE-2026-45697 CRITICAL
Formie: Pre-authenticated server-side template injection in Hidden fields
CVSS 9.8
CVE-2026-49325 MEDIUM
Indian Scout Bobber 2025 WCM voltage-based shutdown
CVSS 4.6
CVE-2026-49316 MEDIUM
Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
CVSS 4.6
CVE-2026-47676 MEDIUM
Hono: app.mount() strips mount prefix using undecoded path, causing incorrect routing for percent-encoded paths
CVSS 5.3
CVE-2026-48792 MEDIUM
pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling remote desktop detection under non-root execution
CVSS 4.4
CVE-2026-45102 CRITICAL
OneUptime: RCE due to Node.js' vm module escape via error objects and infinite recursion
CVSS 9.9
CVE-2026-44451 CRITICAL
Lumiverse: TSX component sandbox escape via DOM ref and string-split identifier bypass
CVSS 9.3
CVE-2026-44071 LOW
Netatalk 3.1.2-4.4.2 - Denial of Service via Missing FORTIFY_SOURCE Protection
CVSS 3.7
CVE-2026-9116 MEDIUM
Google Chrome < 148.0.7778.179 - Cross-Origin Data Leak via ServiceWorker Policy Bypass
CVSS 4.3
CVE-2026-9115 MEDIUM
Google Chrome < 148.0.7778.179 - Same Origin Policy Bypass via Service Worker
CVSS 4.3
CVE-2026-24425 HIGH
Twig 2.16.x & 3.9.0-3.25.x Sandbox Bypass via SourcePolicyInterface
CVSS 8.8
CVE-2026-8969 HIGH
Mitigation bypass in the DOM: Security component
CVSS 8.1
CVE-2026-8962 HIGH
Mitigation bypass in the DOM: Security component
CVSS 8.1
CVE-2026-8959 CRITICAL
Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component
CVSS 9.6
CVE-2026-8958 HIGH
Information disclosure, sandbox escape in the Security: Process Sandboxing component
CVSS 8.6
CVE-2026-8945 HIGH
Sandbox escape in Firefox and Firefox Focus for Android
CVSS 7.5
CVE-2026-8585 HIGH
Google Chrome < 148.0.7778.168 on iOS - Out of Bounds Memory Read in Media
CVSS 7.5
CVE-2026-8583 MEDIUM
Google Chrome < 148.0.7778.168 - Insufficient Policy Enforcement in WebXR
CVSS 5.3
CVE-2026-8572 LOW
Google Chrome < 148.0.7778.168 - Cross-Origin Data Leak via Network Policy Enforcement
CVSS 3.1
CVE-2026-8571 HIGH
Google Chrome < 148.0.7778.168 - Sandbox Escape via GPU Policy Enforcement Bypass
CVSS 8.3
CVE-2026-8563 MEDIUM
Google Chrome < 148.0.7778.168 - Navigation Restriction Bypass via IFrame Sandbox Policy Enforcement
CVSS 4.3
CVE-2026-22707 MEDIUM
Strapi Upload Plugin MIME Validation Bypass via Content API
CVSS 5.4
CVE-2026-30904 LOW
Zoom Workplace < 7.0.0 - Authenticated Information Disclosure via Physical Access
CVSS 1.8
CVE-2026-44003 MEDIUM
vm2: Transformer Fast-Path Bypass Exposes Internal State Variable
CVSS 5.3
Details
Vulnerabilities 669