By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if click
Visual Studio Remote Code Execution Vulnerability
Mattermost Desktop App versions <=5.7.0 fail to correctly prompt for permission when opening external URLs which allows
Due to a Protection Mechanism Failure in SAP NetWeaver Application Server for ABAP and ABAP Platform, a developer can by
Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Aut
Protection mechanism failure for some Intel(R) PROSet/Wireless and Intel(R) Killer(TM) Wi-Fi software before version 22.
RARLAB WinRAR Mark-Of-The-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-Of-The
The Lock User Account plugin for WordPress is vulnerable to user lock bypass in all versions up to, and including, 1.0.5
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Mattermost Desktop App versions <=5.7.0 fail to disable certain Electron debug flags which allows for bypassing TCC rest
Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated u
A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not rec
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JavaFX). S
Mattermost Desktop App versions <=5.8.0 fail to sufficiently configure Electron Fuses which allows an attacker to gather
Nix is a package manager for Linux and other Unix systems. On macOS, built-in builders (such as `builtin:fetchurl`, expo
Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentia
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Securit
An issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.
Microsoft Office Security Feature Bypass Vulnerability
The phone-PC collaboration module has a logic bypass vulnerability. Successful exploitation of this vulnerability may af
NAXSI is an open-source maintenance web application firewall (WAF) for NGINX. An issue present starting in version 1.3 a
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the polic
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially
In getStringsForPrefix of Settings.java, there is a possible prevention of package uninstallation due to a logic error i
In maybeFinish of FallbackHome.java, there is a possible delay of lockdown screen due to logic error. This could lead to
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect d
The HwContacts module has a logic bypass vulnerability. Successful exploitation of this vulnerability may affect data in
Windows Remote Desktop Security Feature Bypass Vulnerability
A protection mechanism failure in Fortinet FortiWeb 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.0 through 6.4.3, 6.3.6
A flaw was found in the tracker-miners package. A weakness in the sandbox allows a maliciously-crafted file to execute c
Dell PowerScale OneFS, 9.5.0.x, contains a protection mechanism bypass vulnerability. An unprivileged, remote attacker
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was
Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version
Inappropriate implementation in in iframe Sandbox in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to b
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not th
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
A vulnerability has been identified in Totally Integrated Automation Portal (TIA Portal) V14 (All versions), Totally Int
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers t
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on Windows devices allows a local user
Protection mechanism failure in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentia
The Metform Elementor Contact Form Builder plugin for WordPress is vulnerable to reCaptcha Bypass in versions up to, and
Protection mechanism failure in some Intel(R) RealSense(TM) ID software for Intel(R) RealSense(TM) 450 FA in version 0.2
An issue was discovered in the Wikibase extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and
Protection mechanism failure in some Intel(R) Distribution of OpenVINO toolkit software before version 2023.0.0 may allo
**DISPUTED**A failure in the -fstack-protector feature in GCC-based toolchains that target AArch64 allows an attacker t
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Frequently Asked Questions
What is CWE-693?
CWE-693 (CWE-693) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-693?
There are 763 CVE records associated with CWE-693 in our database. Of these, 111 are critical severity, 247 are high severity, and 304 are medium severity.
How can I protect against CWE-693 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-693 using AI-powered security agents.
Detect CWE-693 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-693 vulnerabilities across your infrastructure.
Get Started