Protection mechanism failure for some Intel(R) Arc(TM) graphics cards A770 and A750 Limited Edition sold between October
Insufficient policy enforcement in CORS in Google Chrome prior to 109.0.5414.74 allowed a remote attacker to leak cross-
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
A vulnerability was found in Corveda PHPSandbox 1.3.4 and classified as critical. Affected by this issue is some unknown
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowi
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected
Cilium is a networking, observability, and security solution with an eBPF-based dataplane. This issue only impacts users
This issue was addressed with improved checks. This issue is fixed in watchOS 8.7, iOS 15.6 and iPadOS 15.6, macOS Monte
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to
isolated-vm is a library for nodejs which gives the user access to v8's Isolate interface. In versions 4.3.6 and prior,
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scri
This issue was addressed with improved environment sanitization. This issue is fixed in macOS Monterey 12.4. A sandboxed
Protection mechanism failure in the Intel(R) DCM software before version 5.0 may allow an unauthenticated user to potent
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors d
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed con
Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.12.4 for Windows. A local a
A logic issue was addressed with improved checks. This issue is fixed in iOS 15.6 and iPadOS 15.6, tvOS 15.6, macOS Mont
A logic issue was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS
A logic issue was addressed with improved checks. This issue is fixed in iOS 16.2 and iPadOS 16.2, iOS 15.7.2 and iPadOS
A Protection Mechanism Failure vulnerability in the REST API of Juniper Networks Contrail Service Orchestration allows o
Minetest is a free open-source voxel game engine with easy modding and game creation. In **single player**, a mod can se
The HISP module has a vulnerability of bypassing the check of the data transferred in the kernel space.Successful exploi
A logic issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.8, macOS Monterey 12.5, Secu
Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `Wit
Microsoft Excel Security Feature Bypass Vulnerability
The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept heade
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides suffi
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had
Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 105.0.5195.52 allowed a remote atta
A logic issue was addressed with improved checks. This issue is fixed in Safari 16.2, tvOS 16.2, iCloud for Windows 14.1
A vulnerability in the Cisco Umbrella Secure Web Gateway service could allow an unauthenticated, remote attacker to bypa
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic
A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.2, macOS Big Sur 11.7.2, ma
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries).
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security).
Jenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit wh
Jenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not l
Jenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protec
Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-gene
User login brute force protection functionality bypass
A vulnerability exists which could allow an unauthorized user to learn aspects of the communication protocol used to pai
Jenkins XFramium Builder Plugin 1.0.22 and earlier programmatically disables Content-Security-Policy protection for user
Jenkins ScreenRecorder Plugin 0.7 and earlier programmatically disables Content-Security-Policy protection for user-gene
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.
A vulnerability in the automatic decryption process in Cisco Umbrella Secure Web Gateway (SWG) could allow an authentica
Protection mechanism failure in firmware for some Intel(R) SSD DC Products may allow a privileged user to potentially en
In various functions of ap_input_processor.c, there is a possible way to record audio during a phone call due to a logic
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti
Frequently Asked Questions
What is CWE-693?
CWE-693 (CWE-693) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-693?
There are 763 CVE records associated with CWE-693 in our database. Of these, 111 are critical severity, 247 are high severity, and 304 are medium severity.
How can I protect against CWE-693 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-693 using AI-powered security agents.
Detect CWE-693 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-693 vulnerabilities across your infrastructure.
Get Started