Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-693

MITRE ↗

CWE-693

111
CRITICAL
247
HIGH
304
MEDIUM
37
LOW
730 CVEs · Page 4/15
7.9
CVE-2026-48568

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

7.9
CVE-2026-48570

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

7.9
CVE-2026-48575

Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

7.8
CVE-2025-48653

In loadDataAndPostValue of multiple files, there is a possible way to obscure permission usage due to a logic error in t

7.8
CVE-2026-7913

Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 148.0.7778.96 allowed a local attacker

7.8
CVE-2025-48649

In multiple locations, there is a possible way to reset user-selected permissions selections due to a permissions bypass

7.8
CVE-2025-48652

In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in

7.8
CVE-2026-0045

In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic

7.8
CVE-2026-0077

In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a

7.8
CVE-2026-0087

In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app

7.8
CVE-2026-45656

Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.

7.8
CVE-2026-12214

A security flaw has been discovered in Qihoo 360 Total Security 6.0. This vulnerability affects the function RpcStringBi

7.8
CVE-2026-0278

Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow

7.8
CVE-2026-61437

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFl

7.8
CVE-2026-47305

Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-50646

Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.

7.8
CVE-2026-28912

A logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.7

7.8
CVE-2026-54981

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized

7.8
CVE-2026-69278

Incorrect authorization in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.

7.8
CVE-2026-82474

Sudo through 1.9.17p2 fails to apply intercept policy checks to the execveat system call in ptrace-based intercept mode.

7.7
CVE-2025-48635

In multiple functions of TaskFragmentOrganizerController.java, there is a possible activity token leak due to a logic er

7.7
CVE-2026-0017

In onChange of BiometricService.java, there is a possible way to enable fingerprint unlock due to a logic error in the c

7.7
CVE-2026-61792

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

7.6
CVE-2026-54013

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open

7.5
CVE-2025-46290

A logic issue was addressed with improved checks. This issue is fixed in iOS 18.7.3 and iPadOS 18.7.3, iOS 26.2 and iPad

7.5
CVE-2026-2803

Information disclosure, mitigation bypass in the Settings UI component. This vulnerability was fixed in Firefox 148 and

7.5
CVE-2026-20701

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS S

7.5
CVE-2026-22753

Vulnerability in Spring Spring Security. If an application is using securityMatchers(String) and a PathPatternRequestMat

7.5
CVE-2026-43660

A validation issue was addressed with improved logic. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,

7.5
CVE-2026-8585

Inappropriate implementation in Media in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had

7.5
CVE-2026-8945

Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151.

7.5
CVE-2026-57281

Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carr

7.5
CVE-2026-55487

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t

7.5
CVE-2026-14409

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a use

7.5
CVE-2026-48808

Twig is a template language for PHP. Prior to 3.27.0, the column filter passes the active sandbox state as a boolean but

7.5
CVE-2026-70601

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,

7.5
CVE-2026-80198

Kimai versions before 2.56.0 fail to restrict the config() Twig function in sandboxed invoice and export templates, allo

7.3
CVE-2026-48546

KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl

7.2
CVE-2026-44982

CrowdSec offers crowdsourced protection against malicious IPs. From 1.5.0 until 1.7.8, pkg/appsec/request.go NewParsedRe

7.2
CVE-2026-70608

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10

7.1
CVE-2026-42261

PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.

7.1
CVE-2026-13601

A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl.

6.9
CVE-2026-52873

Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until versi

6.8
CVE-2026-14440

Description: To issue and renew TLS certificates on behalf of customers, Cloudflare's Universal SSL feature automati

6.8
CVE-2026-17919

Insufficient policy enforcement in Enterprise in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to

6.8
CVE-2026-76827

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper w

6.5
CVE-2026-24868

Mitigation bypass in the Privacy: Anti-Tracking component. This vulnerability was fixed in Firefox 147.0.2.

6.5
CVE-2026-26994

uTLS is a fork of crypto/tls, created to customize ClientHello for fingerprinting resistance while still using it for th

6.5
CVE-2026-22723

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry

6.5
CVE-2026-20665

This issue was addressed through improved state management. This issue is fixed in Safari 26.4, iOS 18.7.7 and iPadOS 18

Frequently Asked Questions

What is CWE-693?

CWE-693 (CWE-693) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-693?

There are 763 CVE records associated with CWE-693 in our database. Of these, 111 are critical severity, 247 are high severity, and 304 are medium severity.

How can I protect against CWE-693 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-693 using AI-powered security agents.

Detect CWE-693 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-693 vulnerabilities across your infrastructure.

Get Started