CWE-693

Protection Mechanism Failure

The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

669 vulnerabilities with CWE-693
CVE-2026-44000 MEDIUM
vm2: sandbox boundary bypass via host Promise resolution preserving host object identity
CVSS 6.5
CVE-2026-45227 HIGH
Heym < 0.0.21 Sandbox Escape via Python Introspection
CVSS 8.8
CVE-2026-8401 CRITICAL
Firefox < 150.0.3 - Sandbox Escape via Profile Backup Component
CVSS 9.8
CVE-2026-43660 HIGH
iOS and iPadOS < 18.7.9 and < 26.5 - Content Security Policy Bypass via Malicious Web Content
CVSS 7.5
CVE-2026-28914 MEDIUM
Apple macOS <26.5 - Gatekeeper Bypass
CVSS 5.5
CVE-2026-42261 HIGH
PromptHub: Authenticated SSRF via IPv6 filter bypass in `POST /api/skills/fetch-remote`
CVSS 7.1
CVE-2026-41900 HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
CVSS 8.8
CVE-2026-8018 HIGH
Google Chrome < 148.0.7778.96 - Sandbox Escape via DevTools Policy Enforcement
CVSS 8.1
CVE-2026-8014 MEDIUM
Google Chrome < 148.0.7778.96 - Cross-Origin Data Leak via Preload Implementation
CVSS 4.3
CVE-2026-8011 MEDIUM
Google Chrome < 148.0.7778.96 - Cross-Origin Data Leak via Search Policy Enforcement
CVSS 4.3
CVE-2026-8009 MEDIUM
Google Chrome < 148.0.7778.96 - Navigation Restriction Bypass via Cast
CVSS 5.0
CVE-2026-8004 MEDIUM
Google Chrome < 148.0.7778.96 - Insufficient Policy Enforcement in DevTools
CVSS 4.3
CVE-2026-7978 HIGH
Google Chrome < 148.0.7778.96 - OS-Level Privilege Escalation via Companion
CVSS 8.1
CVE-2026-7963 HIGH
Google Chrome < 148.0.7778.96 - Sandbox Escape via ServiceWorker
CVSS 8.3
CVE-2026-7959 LOW
Google Chrome - Site Isolation Bypass
CVSS 3.1
CVE-2026-7952 MEDIUM
Google Chrome < 148.0.7778.96 - Insufficient Policy Enforcement in Extensions
CVSS 4.2
CVE-2026-7946 MEDIUM
Google Chrome - Site Isolation Bypass
CVSS 4.3
CVE-2026-7937 LOW
Google Chrome < 148.0.7778.96 - Insufficient Policy Enforcement in DevTools
CVSS 3.1
CVE-2026-7932 MEDIUM
Google Chrome < 148.0.7778.96 - Insufficient Policy Enforcement in Downloads
CVSS 4.4
CVE-2026-7913 HIGH
Google Chrome < 148.0.7778.96 - Privilege Escalation via DevTools Policy Enforcement
CVSS 7.8
CVE-2026-7909 LOW
Google Chrome < 148.0.7778.96 - Site Isolation Bypass via ServiceWorker
CVSS 3.1
CVE-2026-26956 CRITICAL
vm2: WASM Sandbox Escape (Node 25 only)
CVSS 9.8
CVE-2026-26332 CRITICAL
vm2: Sandbox Escape
CVSS 9.8
CVE-2026-24781 CRITICAL
vm2: Sandbox Breakout Through Inspect
CVSS 9.8
CVE-2026-24120 CRITICAL
vm2: Sandbox Breakout Through Promise Species
CVSS 9.8
Details
Vulnerabilities 669