CWE-693— Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.— MITRE CWE catalog
661 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-693page 8 of 14
- CVE-2025-43728CRITICALCVSS 9.6EG 9.62025-08-27
Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
- CVE-2025-44089HIGHCVSS 8.8EG 8.82026-07-22
An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
- CVE-2025-44090HIGHCVSS 8.8EG 8.82026-07-22
An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted archive file.
- CVE-2025-46281HIGHCVSS 8.8EG 8.82025-12-17
A logic issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.2. An app may be able to break out of its sandbox.
- CVE-2025-46290HIGHCVSS 7.5EG 7.52026-02-11
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPadOS 26.2, macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2, visionOS 26.2, watchOS 26.2. A remote attacker ma…
- CVE-2025-46291HIGHCVSS 7.8EG 7.82025-12-17
A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26.2. An app may bypass Gatekeeper checks.
- CVE-2025-46358HIGHCVSS 7.7EG 7.72025-07-11
Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
- CVE-2025-46553MEDIUMCVSS 6.1EG 6.12025-05-05
@misskey-dev/summaly is a tool for getting a summary of a web page. Starting in version 3.0.1 and prior to version 5.2.1, a logic error in the main `summaly` function causes the `allowRedirects` option to never be passed to any plugins, an…
- CVE-2025-47159HIGHCVSS 7.8EG 7.82025-07-08
Protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.
- CVE-2025-47160MEDIUMCVSS 5.4EG 5.42025-06-10
Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-47984HIGHCVSS 7.5EG 7.52025-07-08
Protection mechanism failure in Windows GDI allows an unauthorized attacker to disclose information over a network.
- CVE-2025-48003MEDIUMCVSS 6.8EG 6.82025-07-08
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-48522HIGHCVSS 7.8EG 7.82025-09-04
In setDisplayName of AssociationRequest.java, there is a possible way for an app to retain CDM association due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. U…
- CVE-2025-48531HIGHCVSS 7.8EG 7.82025-09-04
In getCallingPackageName of CredentialStorage, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not…
- CVE-2025-48534HIGHCVSS 8.8EG 8.82025-09-04
In getDefaultCBRPackageName of CellBroadcastHandler.java, there is a possible escalation of privilege due to a logic error in the code. This could lead to local denial of service with System execution privileges needed. User interaction is…
- CVE-2025-48546HIGHCVSS 7.8EG 7.82025-09-04
In checkPermissions of SafeActivityOptions.java, there is a possible background activity launch due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2025-48554MEDIUMCVSS 6.1EG 6.12025-09-04
In handlePackagesChanged of DevicePolicyManagerService.java, there is a possible persistent denial of service due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User…
- CVE-2025-48571MEDIUMCVSS 4.3EG 4.32026-06-17
In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User …
- CVE-2025-48602HIGHCVSS 8.4EG 8.42026-03-02
In exitKeyguardAndFinishSurfaceBehindRemoteAnimation of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privil…
- CVE-2025-48605HIGHCVSS 8.4EG 8.42026-03-02
In multiple functions of KeyguardViewMediator.java, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction i…
- CVE-2025-48626CRITICALCVSS 9.8EG 9.82025-12-08
In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege with no additional execution privileges needed. User interac…
- CVE-2025-48635HIGHCVSS 7.7EG 7.72026-03-02
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2025-48649HIGHCVSS 7.8EG 7.82026-06-01
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is …
- CVE-2025-48652HIGHCVSS 7.8EG 7.82026-06-01
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User intera…
- CVE-2025-48653HIGHCVSS 7.8EG 7.82026-03-02
In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interact…
- CVE-2025-48800MEDIUMCVSS 6.8EG 6.82025-07-08
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2025-49193MEDIUMCVSS 4.2EG 4.22025-06-12
The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not execu…
- CVE-2025-49740HIGHCVSS 8.8EG 8.82025-07-08
Protection mechanism failure in Windows SmartScreen allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-50324HIGHCVSS 8.8EG 8.82026-07-22
An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneCommander.exe component.
- CVE-2025-50325MEDIUMCVSS 5.4EG 5.42026-07-22
BandiZip v.7.37 is affected by a Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of BandiZip
- CVE-2025-50327HIGHCVSS 8.8EG 8.82026-07-22
An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbitrary code via a bypass of the Mark-of-the-Web protection mechanism
- CVE-2025-50329CRITICALCVSS 9.8EG 9.82026-07-22
An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and execute arbitrary code via the powerarc.exe.
- CVE-2025-50330HIGHCVSS 8.8EG 8.82026-07-22
An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute arbitrary code via the zipgenius.exe.
- CVE-2025-50897MEDIUMCVSS 4.3EG 4.32025-08-19
A vulnerability exists in riscv-boom SonicBOOM 1.2 (BOOMv1.2) processor implementation, where valid virtual-to-physical address translations configured with write permissions (PTE_W) in SV39 mode may incorrectly trigger a Store/AMO access …
- CVE-2025-52609MEDIUMCVSS 5.3EG 5.32026-06-04
HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers.
- CVE-2025-52615LOWCVSS 3.5EG 3.52025-10-12
HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser default treatment for the policies controlled by these headers.
- CVE-2025-52643MEDIUMCVSS 7.8EG 4.72026-03-16
HCL AION is affected by a vulnerability where untrusted file parsing operations are not executed within a properly isolated sandbox environment. This may expose the application to potential security risks, including unintended behaviour or…
- CVE-2025-52951MEDIUMCVSS 5.8EG 5.82025-07-11
A Protection Mechanism Failure vulnerability in kernel filter processing of Juniper Networks Junos OS allows an attacker sending IPv6 traffic destined to the device to effectively bypass any firewall filtering configured on the interface. …
- CVE-2025-54143CRITICALCVSS 9.8EG 9.82025-08-19
Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page. This vulnerability was fixed in Firefox for iOS 141.
- CVE-2025-54917MEDIUMCVSS 4.3EG 4.32025-09-09
Protection mechanism failure in Windows MapUrlToZone allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2025-55249LOWCVSS 5.3EG 3.52026-01-19
HCL AION is affected by a Missing Security Response Headers vulnerability. The absence of standard security headers may weaken the application’s overall security posture and increase its susceptibility to common web-based attacks.
- CVE-2025-55886HIGHCVSS 6.5EG 7.52025-09-22
An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment hi…
- CVE-2025-58406MEDIUMCVSS 4.3EG 4.32026-03-02
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security contro…
- CVE-2025-59033CRITICALCVSS 7.4EG 9.82025-09-08
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that sp…
- CVE-2025-59849MEDIUMCVSS 4.7EG 4.72025-12-17
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- CVE-2025-60711MEDIUMCVSS 6.3EG 6.32025-10-31
Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- CVE-2025-62453MEDIUMCVSS 5.0EG 5.02025-11-11
Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.
- CVE-2025-6427CRITICALCVSS 9.1EG 9.12025-06-24
An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. This would have also hidden the connections from the Network tab in Devtools. This vulnerability was fixed in Firefox 140…
- CVE-2025-64763MEDIUMCVSS 5.3EG 5.32025-12-03
Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it accepts client data before issuing a 2xx response and forwar…
- CVE-2025-65100MEDIUMCVSS 6.9EG 6.92025-11-19
Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp value for security distribution, leading to missed security upd…
Map vulnerabilities like CWE-693 to your infrastructure
EchelonGraph correlates every CVE — across CWE-693 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →