Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-693

MITRE ↗

CWE-693

111
CRITICAL
247
HIGH
304
MEDIUM
37
LOW
730 CVEs · Page 11/15
7.5
CVE-2024-0804

Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to

7.5
CVE-2024-31142

Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intende

7.5
CVE-2024-0101

NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter

7.3
CVE-2024-38226 KEV

Microsoft Publisher Security Feature Bypass Vulnerability

7.2
CVE-2024-28248

Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Starting in version 1.13.9 an

6.8
CVE-2024-38058

BitLocker Security Feature Bypass Vulnerability

6.7
CVE-2023-25945

Protection mechanism failure in some Intel(R) OFU software before version 14.1.31 may allow an authenticated user to pot

6.7
CVE-2024-20669

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2024-26250

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2024-28903

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2024-28919

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2024-28921

Secure Boot Security Feature Bypass Vulnerability

6.7
CVE-2024-43645

Windows Defender Application Control (WDAC) Security Feature Bypass Vulnerability

6.5
CVE-2024-0747

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overr

6.5
CVE-2024-1671

Inappropriate implementation in Site Isolation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypa

6.5
CVE-2024-23284

A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16

6.5
CVE-2023-39368

Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to pot

6.5
CVE-2024-38213 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

6.5
CVE-2024-23499

Protection mechanism failure in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters E81

6.5
CVE-2024-24983

Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before

6.5
CVE-2024-43487

Windows Mark of the Web Security Feature Bypass Vulnerability

6.5
CVE-2024-46976

Backstage is an open framework for building developer portals. An attacker with control of the contents of the TechDocs

6.4
CVE-2022-48219

Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which

6.4
CVE-2024-43513

BitLocker Security Feature Bypass Vulnerability

6.3
CVE-2024-29510

Artifex Ghostscript before 10.03.1 allows memory corruption, and SAFER sandbox bypass, via format string injection with

6.3
CVE-2023-42918

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed proc

6.3
CVE-2024-20438

A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to

6.2
CVE-2024-38203

Windows Package Library Manager Information Disclosure Vulnerability

6.1
CVE-2023-22655

Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel

6.1
CVE-2024-20665

BitLocker Security Feature Bypass Vulnerability

6.1
CVE-2024-24980

Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged use

5.9
CVE-2024-20926

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

5.9
CVE-2024-33903

In CARLA through 0.9.15.2, the collision sensor mishandles some situations involving pedestrians or bicycles, in part be

5.8
CVE-2024-6741

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers c

5.8
CVE-2021-1494

Multiple Cisco products are affected by a vulnerability in the Snort detection engine that could allow an unauthenticate

5.5
CVE-2024-43585

Code Integrity Guard Security Feature Bypass Vulnerability

5.4
CVE-2024-24562

vantage6-UI is the official user interface for the vantage6 server. In affected versions a number of security headers ar

5.4
CVE-2024-30041

Microsoft Bing Search Spoofing Vulnerability

5.4
CVE-2024-30050

Windows Mark of the Web Security Feature Bypass Vulnerability

5.4
CVE-2024-38874

An issue was discovered in the events2 (aka Events 2) extension before 8.3.8 and 9.x before 9.0.6 for TYPO3. Missing acc

5.4
CVE-2024-38217 KEV

Windows Mark of the Web Security Feature Bypass Vulnerability

5.3
CVE-2024-0680

The WP Private Content Plus plugin for WordPress is vulnerable to information disclosure in all versions up to, and incl

5.3
CVE-2024-0682

The Page Restrict plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 2.5

5.3
CVE-2024-0681

The Page Restriction WordPress (WP) – Protect WP Pages/Post plugin for WordPress is vulnerable to information disclosure

5.3
CVE-2024-20284

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at

5.3
CVE-2024-20286

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, low-privileged, local at

5.3
CVE-2022-4100

The WP Cerber Security plugin for WordPress is vulnerable to IP Protection bypass in versions up to, and including 9.4 d

4.8
CVE-2024-21423

Microsoft Edge (Chromium-based) Information Disclosure Vulnerability

4.8
CVE-2024-39836

Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 and 9.8.x <= 9.8.2 fail to ensure that remote/synt

4.7
CVE-2024-26163

Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Frequently Asked Questions

What is CWE-693?

CWE-693 (CWE-693) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-693?

There are 763 CVE records associated with CWE-693 in our database. Of these, 111 are critical severity, 247 are high severity, and 304 are medium severity.

How can I protect against CWE-693 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-693 using AI-powered security agents.

Detect CWE-693 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-693 vulnerabilities across your infrastructure.

Get Started