CWE-693— Protection Mechanism Failure
484 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-693page 8 of 10
- CVE-2025-48522HIGHCVSS 7.8EG 7.82025-09-04
In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2025-48531HIGHCVSS 7.8EG 7.82025-09-04
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- CVE-2025-48534HIGHCVSS 8.8EG 8.82025-09-04
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is…
- CVE-2025-48546HIGHCVSS 7.8EG 7.82025-09-04
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2025-48554MEDIUMCVSS 6.1EG 6.12025-09-04
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User…
- CVE-2025-48626CRITICALCVSS 9.8EG 9.82025-12-08
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2025-48649HIGHCVSS 7.8EG 0.02026-06-01
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2025-48652HIGHCVSS 7.8EG 0.02026-06-01
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
- CVE-2025-48800MEDIUMCVSS 6.8EG 6.82025-07-08
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-49193MEDIUMCVSS 4.2EG 4.22025-06-12
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not execu…
- CVE-2025-49740HIGHCVSS 8.8EG 8.82025-07-08
Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-50897MEDIUMCVSS 4.3EG 4.32025-08-19
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access …
- CVE-2025-52615LOWCVSS 3.5EG 3.52025-10-12
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.
- CVE-2025-52951MEDIUMCVSS 5.8EG 5.82025-07-11
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to effectively bypass any firewall filtering configured on the interface. …
- CVE-2025-54143CRITICALCVSS 9.8EG 9.82025-08-19
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
- CVE-2025-54917MEDIUMCVSS 4.3EG 4.32025-09-09
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-55249LOWCVSS 3.5EG 3.52026-01-19
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.
- CVE-2025-55886MEDIUMCVSS 6.5EG 7.52025-09-22
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment hi…
- CVE-2025-59033HIGHCVSS 7.4EG 9.82025-09-08
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that sp…
- CVE-2025-59849MEDIUMCVSS 4.7EG 4.72025-12-17
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- CVE-2025-60711MEDIUMCVSS 6.3EG 6.32025-10-31
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2025-62453MEDIUMCVSS 5.0EG 5.02025-11-11
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
- CVE-2025-6427CRITICALCVSS 9.1EG 9.12025-06-24
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140…
- CVE-2025-64763LOWCVSS 3.7EG 3.72025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwar…
- CVE-2025-65100MEDIUMCVSS 6.9EG 0.02025-11-19
Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distribution, leading to missed security upd…
- CVE-2025-65318CRITICALCVSS 9.1EG 9.12025-12-16
When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS a…
- CVE-2025-65319CRITICALCVSS 9.1EG 9.12025-12-16
When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass the built-in file protection mechanisms of both Windows OS …
- CVE-2025-66204HIGHCVSS 8.1EG 8.12025-12-09
WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For` on each request, gaining unlimited password guessing attemp…
- CVE-2025-66479LOWCVSS 1.8EG 0.02025-12-04
Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container. Prior to 0.0.16, due to a bug in sandboxing logic, sandbox-…
- CVE-2025-67460HIGHCVSS 7.8EG 7.82025-12-10
Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.
- CVE-2025-67485MEDIUMCVSS 5.3EG 5.32025-12-10
mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to bypass HTTP/HTTPS traffic interception rules, potentially ex…
- CVE-2025-68668CRITICALCVSS 9.9EG 9.92025-12-26
n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability exists in the Python Code Node that uses Pyodide. An authenticated user with permission to create or modify workflows ca…
- CVE-2025-69264HIGHCVSS 8.8EG 8.82026-01-07
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Whil…
- CVE-2025-8032HIGHCVSS 8.1EG 8.12025-07-22
XSLT document loading did not correctly propagate the source document which bypassed its CSP. This vulnerability was fixed in Firefox 141, Firefox ESR 128.13, Firefox ESR 140.1, Thunderbird 141, Thunderbird 128.13, and Thunderbird 140.1.
- CVE-2025-8656MEDIUMCVSS 6.8EG 6.82025-08-06
Kenwood DMX958XR Protection Mechanism Failure Software Downgrade Vulnerability. This vulnerability allows physically present attackers to downgrade software on affected installations of Kenwood DMX958XR devices. Authentication is not requi…
- CVE-2025-9866HIGHCVSS 8.8EG 8.82025-09-03
Inappropriate implementation in Extensions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-0045HIGHCVSS 7.8EG 0.02026-06-01
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
- CVE-2026-0077HIGHCVSS 7.8EG 0.02026-06-01
In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges neede…
- CVE-2026-0087HIGHCVSS 7.8EG 0.02026-06-01
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of privilege with no additional execution pr…
- CVE-2026-0097HIGHCVSS 8.0EG 0.02026-06-01
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed.…
- CVE-2026-0620MEDIUMCVSS 6.0EG 0.02026-02-03
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising con…
- CVE-2026-0877HIGHCVSS 8.1EG 8.12026-01-13
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 147, Firefox ESR 115.32, Firefox ESR 140.7, Thunderbird 147, and Thunderbird 140.7.
- CVE-2026-0881CRITICALCVSS 10.0EG 10.02026-01-13
Sandbox escape in the Messaging System component. This vulnerability was fixed in Firefox 147 and Thunderbird 147.
- CVE-2026-10174MEDIUMCVSS 6.3EG 6.32026-05-31
A vulnerability was identified in Aider-AI Aider 0.86.3. Affected is an unknown function of the file aider/args.py of the component Pre-commit Hook Handler. Such manipulation of the argument git-commit-verify leads to protection mechanism …
- CVE-2026-1232MEDIUMCVSS 6.8EG 0.02026-02-02
A medium-severity vulnerability has been identified in BeyondTrust Privilege Management for Windows versions <=25.7. Under certain conditions, a local authenticated user with elevated privileges may be able to bypass the product’s anti-t…
- CVE-2026-20667HIGHCVSS 8.8EG 8.82026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.3, watchOS 26.3. An app may be able to break out of its sandbox.
- CVE-2026-20824MEDIUMCVSS 5.5EG 5.52026-01-13
Protection mechanism failure in Windows Remote Assistance allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-21510HIGHCVSS 8.8EG 9.0⚠ KEV2026-02-10
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-21513HIGHCVSS 8.8EG 9.0⚠ KEV2026-02-10
Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-22013MEDIUMCVSS 5.3EG 5.32026-04-21
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17…
Map vulnerabilities like CWE-693 to your infrastructure
EchelonGraph correlates every CVE — across CWE-693 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →