Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t
Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker
In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in
In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic
In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBi
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow
PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7
Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized
Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode.
In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er
In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open
A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad
Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS S
Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat
A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,
Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had
Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carr
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a use
Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,
Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allo
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl
CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10
PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.
A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl.
Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until versi
Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati
Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to
A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper w
Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.
uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry
This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18
Frequently Asked Questions
What is CWE-693?
CWE-693 (CWE-693) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-693?
There are 763 CVE records associated with CWE-693 in our database. Of these, 111 are critical severity, 247 are high severity, and 304 are medium severity.
How can I protect against CWE-693 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-693 using AI-powered security agents.
Detect CWE-693 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-693 vulnerabilities across your infrastructure.
Get Started