CWE-693 · 768 records
Protection Mechanism Failure
CVEs in this class
768 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2013-2465Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Critical9.8 | KEV | 98.8% | Jun 18, 2013 |
98Now | CVE-2019-1003030Weaponized | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wojenkins · pipeline\ · CWE-693 | Critical9.9 | KEV | 96.9% | Mar 8, 2019 |
92Now | CVE-2024-21412Weaponized | Internet Shortcut Files Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1809 · CWE-693 | High8.1 | KEV | 99.4% | Feb 13, 2024 |
91Now | CVE-2025-40536Weaponized | SolarWinds Web Help Desk Security Control Bypass Vulnerabilitysolarwinds · web help desk · CWE-693 | Critical9.8 | KEV | 73.6% | Jan 28, 2026 |
78This week | CVE-2013-0431Weaponized | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-oracle · jre · CWE-693 | Medium5.3 | KEV | 90.2% | Jan 31, 2013 |
78This week | CVE-2025-0411Weaponized | 7-Zip Mark-of-the-Web Bypass Vulnerability7-zip · 7-zip · CWE-693 | High7.0 | KEV | 67.1% | Jan 25, 2025 |
78This week | CVE-2024-29988Weaponized | SmartScreen Prompt Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1809 · CWE-693 | High8.8 | KEV | 44.9% | Apr 9, 2024 |
72This week | CVE-2026-21510Weaponized | Windows Shell Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | High8.8 | KEV | 24.2% | Feb 10, 2026 |
70This week | CVE-2026-21513Weaponized | MSHTML Framework Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | High8.8 | KEV | 15.6% | Feb 10, 2026 |
60This week | CVE-2024-38213Weaponized | Windows Mark of the Web Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-693 | Medium6.5 | KEV | 13.6% | Aug 13, 2024 |
60This week | CVE-2024-38226Weaponized | Microsoft Publisher Security Feature Bypass Vulnerabilitymicrosoft · office 2019 · CWE-693 | High7.3 | KEV | 2.7% | Sep 10, 2024 |
54Plan | CVE-2024-38217Weaponized | Windows Mark of the Web Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-693 | Medium5.4 | KEV | 10.0% | Sep 10, 2024 |
53Plan | CVE-2024-34144Proof of concept | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allowsjenkins · script security · CWE-693 | Critical9.8 | — | 48.1% | May 2, 2024 |
48Plan | CVE-2026-32202Weaponized | Windows Shell Spoofing Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Medium4.3 | KEV | 4.9% | Apr 14, 2026 |
43Plan | CVE-2025-68668No exploit | n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Noden8n · n8n · CWE-693 | Critical9.9 | — | 13.2% | Dec 26, 2025 |
42Plan | CVE-2022-32845No exploit | This issue was addressed with improved checks.apple · ipados · CWE-693 | Critical10.0 | — | 5.4% | Sep 23, 2022 |
41Plan | CVE-2017-3197No exploit | GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protectiongigabyte · gb-bsi7h-6500 firmware · CWE-693 | Critical9.8 | — | 5.6% | Jul 9, 2018 |
41Plan | CVE-2022-35978Proof of concept | Lua sandbox escape from mod in Minetestminetest · minetest · CWE-693 | Critical10.0 | — | 2.9% | Aug 15, 2022 |
40Plan | CVE-2021-32835No exploit | Groovy Sandbox escape in Eclipse Ketieclipse · keti · CWE-693 | Critical9.9 | — | 4.6% | Sep 8, 2021 |
40Plan | CVE-2018-9318No exploit | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a rbmw · telematics control unit firmware · CWE-693 | Critical9.8 | — | 4.3% | May 31, 2018 |
40Plan | CVE-2018-9311No exploit | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a rbmw · telematics control unit firmware · CWE-693 | Critical9.8 | — | 4.0% | May 31, 2018 |
40Plan | CVE-2020-10887No exploit | This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.tp-link · ac1750 firmware · CWE-693 | Critical9.8 | — | 3.7% | Mar 25, 2020 |
40Plan | CVE-2022-31479No exploit | Remote Code Execution via command injection of the hostnamehidglobal · lp1501 firmware · CWE-693 | Critical9.8 | — | 2.4% | Jun 6, 2022 |
40Plan | CVE-2017-8864No exploit | Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent tocohuhd · 3960hd firmware · CWE-693 | Critical9.8 | — | 2.3% | Nov 22, 2017 |
40Plan | CVE-2019-10328No exploit | Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitjenkins · pipeline remote loader · CWE-693 | Critical9.9 | — | 1.9% | May 31, 2019 |
- CVE-2013-246599Now
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
CriticalCVSS 9.8KEVWeaponizedEPSS 99%oracle · jreJun 18, 2013
- CVE-2019-100303098Now
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo
CriticalCVSS 9.9KEVWeaponizedEPSS 97%jenkins · pipeline\Mar 8, 2019
- CVE-2024-2141292Now
Internet Shortcut Files Security Feature Bypass Vulnerability
HighCVSS 8.1KEVWeaponizedEPSS 99%microsoft · windows 10 1809Feb 13, 2024
- CVE-2025-4053691Now
SolarWinds Web Help Desk Security Control Bypass Vulnerability
CriticalCVSS 9.8KEVWeaponizedEPSS 74%solarwinds · web help deskJan 28, 2026
- CVE-2013-043178This week
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-
MediumCVSS 5.3KEVWeaponizedEPSS 90%oracle · jreJan 31, 2013
- CVE-2025-041178This week
7-Zip Mark-of-the-Web Bypass Vulnerability
HighCVSS 7.0KEVWeaponizedEPSS 67%7-zip · 7-zipJan 25, 2025
- CVE-2024-2998878This week
SmartScreen Prompt Security Feature Bypass Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 45%microsoft · windows 10 1809Apr 9, 2024
- CVE-2026-2151072This week
Windows Shell Security Feature Bypass Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 24%microsoft · windows 10 1607Feb 10, 2026
- CVE-2026-2151370This week
MSHTML Framework Security Feature Bypass Vulnerability
HighCVSS 8.8KEVWeaponizedEPSS 16%microsoft · windows 10 1607Feb 10, 2026
- CVE-2024-3821360This week
Windows Mark of the Web Security Feature Bypass Vulnerability
MediumCVSS 6.5KEVWeaponizedEPSS 14%microsoft · windows 10 1507Aug 13, 2024
- CVE-2024-3822660This week
Microsoft Publisher Security Feature Bypass Vulnerability
HighCVSS 7.3KEVWeaponizedEPSS 3%microsoft · office 2019Sep 10, 2024
- CVE-2024-3821754Plan
Windows Mark of the Web Security Feature Bypass Vulnerability
MediumCVSS 5.4KEVWeaponizedEPSS 10%microsoft · windows 10 1507Sep 10, 2024
- CVE-2024-3414453Plan
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows
CriticalCVSS 9.8Proof of conceptEPSS 48%jenkins · script securityMay 2, 2024
- CVE-2026-3220248Plan
Windows Shell Spoofing Vulnerability
MediumCVSS 4.3KEVWeaponizedEPSS 5%microsoft · windows 10 1607Apr 14, 2026
- CVE-2025-6866843Plan
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
CriticalCVSS 9.9No exploitEPSS 13%n8n · n8nDec 26, 2025
- CVE-2022-3284542Plan
This issue was addressed with improved checks.
CriticalCVSS 10.0No exploitEPSS 5%apple · ipadosSep 23, 2022
- CVE-2017-319741Plan
GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
CriticalCVSS 9.8No exploitEPSS 6%gigabyte · gb-bsi7h-6500 firmwareJul 9, 2018
- CVE-2022-3597841Plan
Lua sandbox escape from mod in Minetest
CriticalCVSS 10.0Proof of conceptEPSS 3%minetest · minetestAug 15, 2022
- CVE-2021-3283540Plan
Groovy Sandbox escape in Eclipse Keti
CriticalCVSS 9.9No exploitEPSS 5%eclipse · ketiSep 8, 2021
- CVE-2018-931840Plan
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r
CriticalCVSS 9.8No exploitEPSS 4%bmw · telematics control unit firmwareMay 31, 2018
- CVE-2018-931140Plan
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r
CriticalCVSS 9.8No exploitEPSS 4%bmw · telematics control unit firmwareMay 31, 2018
- CVE-2020-1088740Plan
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.
CriticalCVSS 9.8No exploitEPSS 4%tp-link · ac1750 firmwareMar 25, 2020
- CVE-2022-3147940Plan
Remote Code Execution via command injection of the hostname
CriticalCVSS 9.8No exploitEPSS 2%hidglobal · lp1501 firmwareJun 6, 2022
- CVE-2017-886440Plan
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to
CriticalCVSS 9.8No exploitEPSS 2%cohuhd · 3960hd firmwareNov 22, 2017
- CVE-2019-1032840Plan
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbit
CriticalCVSS 9.9No exploitEPSS 2%jenkins · pipeline remote loaderMay 31, 2019