Skip to content
Noroxi

CWE-693 · 768 records

Protection Mechanism Failure

CVEs in this class

768 records

  • Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    oracle · jreJun 18, 2013

  • A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo

    CriticalCVSS 9.9KEVWeaponizedEPSS 97%

    jenkins · pipeline\Mar 8, 2019

  • Internet Shortcut Files Security Feature Bypass Vulnerability

    HighCVSS 8.1KEVWeaponizedEPSS 99%

    microsoft · windows 10 1809Feb 13, 2024

  • SolarWinds Web Help Desk Security Control Bypass Vulnerability

    CriticalCVSS 9.8KEVWeaponizedEPSS 74%

    solarwinds · web help deskJan 28, 2026

  • CVE-2013-0431
    78This week

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-

    MediumCVSS 5.3KEVWeaponizedEPSS 90%

    oracle · jreJan 31, 2013

  • CVE-2025-0411
    78This week

    7-Zip Mark-of-the-Web Bypass Vulnerability

    HighCVSS 7.0KEVWeaponizedEPSS 67%

    7-zip · 7-zipJan 25, 2025

  • CVE-2024-29988
    78This week

    SmartScreen Prompt Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 45%

    microsoft · windows 10 1809Apr 9, 2024

  • CVE-2026-21510
    72This week

    Windows Shell Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 24%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2026-21513
    70This week

    MSHTML Framework Security Feature Bypass Vulnerability

    HighCVSS 8.8KEVWeaponizedEPSS 16%

    microsoft · windows 10 1607Feb 10, 2026

  • CVE-2024-38213
    60This week

    Windows Mark of the Web Security Feature Bypass Vulnerability

    MediumCVSS 6.5KEVWeaponizedEPSS 14%

    microsoft · windows 10 1507Aug 13, 2024

  • CVE-2024-38226
    60This week

    Microsoft Publisher Security Feature Bypass Vulnerability

    HighCVSS 7.3KEVWeaponizedEPSS 3%

    microsoft · office 2019Sep 10, 2024

  • Windows Mark of the Web Security Feature Bypass Vulnerability

    MediumCVSS 5.4KEVWeaponizedEPSS 10%

    microsoft · windows 10 1507Sep 10, 2024

  • A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows

    CriticalCVSS 9.8Proof of conceptEPSS 48%

    jenkins · script securityMay 2, 2024

  • Windows Shell Spoofing Vulnerability

    MediumCVSS 4.3KEVWeaponizedEPSS 5%

    microsoft · windows 10 1607Apr 14, 2026

  • n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node

    CriticalCVSS 9.9No exploitEPSS 13%

    n8n · n8nDec 26, 2025

  • This issue was addressed with improved checks.

    CriticalCVSS 10.0No exploitEPSS 5%

    apple · ipadosSep 23, 2022

  • GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection

    CriticalCVSS 9.8No exploitEPSS 6%

    gigabyte · gb-bsi7h-6500 firmwareJul 9, 2018

  • Lua sandbox escape from mod in Minetest

    CriticalCVSS 10.0Proof of conceptEPSS 3%

    minetest · minetestAug 15, 2022

  • Groovy Sandbox escape in Eclipse Keti

    CriticalCVSS 9.9No exploitEPSS 5%

    eclipse · ketiSep 8, 2021

  • The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r

    CriticalCVSS 9.8No exploitEPSS 4%

    bmw · telematics control unit firmwareMay 31, 2018

  • The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r

    CriticalCVSS 9.8No exploitEPSS 4%

    bmw · telematics control unit firmwareMay 31, 2018

  • This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.

    CriticalCVSS 9.8No exploitEPSS 4%

    tp-link · ac1750 firmwareMar 25, 2020

  • Remote Code Execution via command injection of the hostname

    CriticalCVSS 9.8No exploitEPSS 2%

    hidglobal · lp1501 firmwareJun 6, 2022

  • Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to

    CriticalCVSS 9.8No exploitEPSS 2%

    cohuhd · 3960hd firmwareNov 22, 2017

  • Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbit

    CriticalCVSS 9.9No exploitEPSS 2%

    jenkins · pipeline remote loaderMay 31, 2019

All vulnerability classes