CWE-693
627 CVEs • Abstraction: Pillar
Protection Mechanism Failure
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
CVEs (627)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Compuware Topaz Utilities Jun 17, 2026 Oct 19, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executed, allowing attackers able to control agent processes to obtain the values of J...Show more |
4Azul FedoraprojectNetapp+1 more157 Mode Transition Tool Cloud Insights Acquisition UnitCloud Secure Agent+12 moreJun 17, 2026 Oct 18, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1; Oracle GraalV...Show more |
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic error in the code. This could lead to local information disclosure with User execution privileges n...Show more |
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploitation of this vulnerability may cause unauthorized access to the HISP module. |
1Isolated Vm Project 1Isolated Vm Jun 17, 2026 Sep 29, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior, if the untrusted v8 cached data is passed to the API through CachedDataOptions, attackers can bypass...Show more |
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to bypass content security policy via a crafted HTML page. |
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. |
1Apple 4Ipados Iphone OsMacos+1 moreJun 17, 2026 Sep 23, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5. An app may be able to break out of its sandbox. |
A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Monterey 12.5. Processing a maliciously crafted file may lead to arbitrary code execution. |
This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed process may be able to circumvent sandbox restrictions. |
1Intel 30Ssd 600p Firmware Ssd 660p FirmwareSsd 665p Firmware+27 moreJun 17, 2026 Sep 20, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disclosure via local access. |
1Intel 30Ssd 600p Firmware Ssd 660p FirmwareSsd 665p Firmware+27 moreJun 17, 2026 Sep 20, 2022 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially enable information disclosure via local access. |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded fo...Show more |
1Openpolicyagent 1Open Policy Agent Jun 17, 2026 Sep 8, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be...Show more |
Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can set a global setting that controls the Lua script loaded to display the main menu. The script is then...Show more |
1Microsoft 4365 Apps ExcelOffice+1 moreJun 17, 2026 Aug 9, 2022 N/A· v4 7.3 HIGH· v3 N/A· v2 Microsoft Excel Security Feature Bypass Vulnerability |
2Carrier Hidglobal14Ep4502 Firmware Lenels2 Lnl 4420 FirmwareLenels2 Lnl X2210 Firmware+11 moreJun 17, 2026 Jun 6, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mer...Show more |
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local attacker may be able to elevate their privileges. |
1Cisco 1Umbrella Secure Web Gateway Jun 17, 2026 Apr 21, 2022 N/A· v4 4.1 MEDIUM· v3 2.7 LOW· v2 A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authenticated, adjacent attacker to bypass the SSL decryption and content filtering policies on an affected sy...Show more |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Apr 1, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security...Show more |