CWE-693 · 782 записей
Protection Mechanism Failure
CVE этого класса
782 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2013-2465Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlieroracle · jre · CWE-693 | Критическая9,8 | KEV | 98,8 % | 18 июн. 2013 г. |
98Срочно | CVE-2019-1003030Готовый эксплойт | A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wojenkins · pipeline\ · CWE-693 | Критическая9,9 | KEV | 97,1 % | 8 мар. 2019 г. |
92Срочно | CVE-2024-21412Готовый эксплойт | Internet Shortcut Files Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1809 · CWE-693 | Высокая8,1 | KEV | 99,4 % | 13 февр. 2024 г. |
91Срочно | CVE-2025-40536Готовый эксплойт | SolarWinds Web Help Desk Security Control Bypass Vulnerabilitysolarwinds · web help desk · CWE-693 | Критическая9,8 | KEV | 73,6 % | 28 янв. 2026 г. |
78На этой неделе | CVE-2025-0411Готовый эксплойт | 7-Zip Mark-of-the-Web Bypass Vulnerability7-zip · 7-zip · CWE-693 | Высокая7,0 | KEV | 67,1 % | 25 янв. 2025 г. |
78На этой неделе | CVE-2024-29988Готовый эксплойт | SmartScreen Prompt Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1809 · CWE-693 | Высокая8,8 | KEV | 44,9 % | 9 апр. 2024 г. |
72На этой неделе | CVE-2026-21510Готовый эксплойт | Windows Shell Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Высокая8,8 | KEV | 24,5 % | 10 февр. 2026 г. |
71На этой неделе | CVE-2013-0431Готовый эксплойт | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-oracle · jre · CWE-693 | Низкая3,7 | KEV | 90,2 % | 31 янв. 2013 г. |
70На этой неделе | CVE-2026-21513Готовый эксплойт | MSHTML Framework Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Высокая8,8 | KEV | 15,9 % | 10 февр. 2026 г. |
60На этой неделе | CVE-2024-38213Готовый эксплойт | Windows Mark of the Web Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-693 | Средняя6,5 | KEV | 13,6 % | 13 авг. 2024 г. |
60На этой неделе | CVE-2024-38226Готовый эксплойт | Microsoft Publisher Security Feature Bypass Vulnerabilitymicrosoft · office 2019 · CWE-693 | Высокая7,3 | KEV | 2,7 % | 10 сент. 2024 г. |
54В плане | CVE-2024-38217Готовый эксплойт | Windows Mark of the Web Security Feature Bypass Vulnerabilitymicrosoft · windows 10 1507 · CWE-693 | Средняя5,4 | KEV | 10,0 % | 10 сент. 2024 г. |
53В плане | CVE-2024-34144Proof of concept | A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allowsjenkins · script security · CWE-693 | Критическая9,8 | — | 48,1 % | 2 мая 2024 г. |
48В плане | CVE-2026-32202Готовый эксплойт | Windows Shell Spoofing Vulnerabilitymicrosoft · windows 10 1607 · CWE-693 | Средняя4,3 | KEV | 4,9 % | 14 апр. 2026 г. |
43В плане | CVE-2025-68668Эксплойта нет | n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Noden8n · n8n · CWE-693 | Критическая9,9 | — | 13,2 % | 26 дек. 2025 г. |
42В плане | CVE-2022-32845Эксплойта нет | This issue was addressed with improved checks.apple · ipados · CWE-693 | Критическая10,0 | — | 5,4 % | 23 сент. 2022 г. |
41В плане | CVE-2017-3197Эксплойта нет | GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protectiongigabyte · gb-bsi7h-6500 firmware · CWE-693 | Критическая9,8 | — | 5,6 % | 9 июл. 2018 г. |
41В плане | CVE-2022-35978Proof of concept | Lua sandbox escape from mod in Minetestminetest · minetest · CWE-693 | Критическая10,0 | — | 2,9 % | 15 авг. 2022 г. |
40В плане | CVE-2021-32835Эксплойта нет | Groovy Sandbox escape in Eclipse Ketieclipse · keti · CWE-693 | Критическая9,9 | — | 4,6 % | 8 сент. 2021 г. |
40В плане | CVE-2018-9318Эксплойта нет | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a rbmw · telematics control unit firmware · CWE-693 | Критическая9,8 | — | 4,2 % | 31 мая 2018 г. |
40В плане | CVE-2018-9311Эксплойта нет | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a rbmw · telematics control unit firmware · CWE-693 | Критическая9,8 | — | 3,9 % | 31 мая 2018 г. |
40В плане | CVE-2020-10887Эксплойта нет | This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.tp-link · ac1750 firmware · CWE-693 | Критическая9,8 | — | 3,7 % | 25 мар. 2020 г. |
40В плане | CVE-2022-31479Эксплойта нет | Remote Code Execution via command injection of the hostnamehidglobal · lp1501 firmware · CWE-693 | Критическая9,8 | — | 2,4 % | 6 июн. 2022 г. |
40В плане | CVE-2017-8864Эксплойта нет | Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent tocohuhd · 3960hd firmware · CWE-693 | Критическая9,8 | — | 2,3 % | 22 нояб. 2017 г. |
40В плане | CVE-2019-10328Эксплойта нет | Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbitjenkins · pipeline remote loader · CWE-693 | Критическая9,9 | — | 1,9 % | 31 мая 2019 г. |
- CVE-2013-246599Срочно
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %oracle · jre18 июн. 2013 г.
- CVE-2019-100303098Срочно
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/wo
КритическаяCVSS 9,9KEVГотовый эксплойтEPSS 97 %jenkins · pipeline\8 мар. 2019 г.
- CVE-2024-2141292Срочно
Internet Shortcut Files Security Feature Bypass Vulnerability
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 99 %microsoft · windows 10 180913 февр. 2024 г.
- CVE-2025-4053691Срочно
SolarWinds Web Help Desk Security Control Bypass Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %solarwinds · web help desk28 янв. 2026 г.
- CVE-2025-041178На этой неделе
7-Zip Mark-of-the-Web Bypass Vulnerability
ВысокаяCVSS 7,0KEVГотовый эксплойтEPSS 67 %7-zip · 7-zip25 янв. 2025 г.
- CVE-2024-2998878На этой неделе
SmartScreen Prompt Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 45 %microsoft · windows 10 18099 апр. 2024 г.
- CVE-2026-2151072На этой неделе
Windows Shell Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 25 %microsoft · windows 10 160710 февр. 2026 г.
- CVE-2013-043171На этой неделе
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-
НизкаяCVSS 3,7KEVГотовый эксплойтEPSS 90 %oracle · jre31 янв. 2013 г.
- CVE-2026-2151370На этой неделе
MSHTML Framework Security Feature Bypass Vulnerability
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 16 %microsoft · windows 10 160710 февр. 2026 г.
- CVE-2024-3821360На этой неделе
Windows Mark of the Web Security Feature Bypass Vulnerability
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 14 %microsoft · windows 10 150713 авг. 2024 г.
- CVE-2024-3822660На этой неделе
Microsoft Publisher Security Feature Bypass Vulnerability
ВысокаяCVSS 7,3KEVГотовый эксплойтEPSS 3 %microsoft · office 201910 сент. 2024 г.
- CVE-2024-3821754В плане
Windows Mark of the Web Security Feature Bypass Vulnerability
СредняяCVSS 5,4KEVГотовый эксплойтEPSS 10 %microsoft · windows 10 150710 сент. 2024 г.
- CVE-2024-3414453В плане
A sandbox bypass vulnerability involving crafted constructor bodies in Jenkins Script Security Plugin 1335.vf07d9ce377a_e and earlier allows
КритическаяCVSS 9,8Proof of conceptEPSS 48 %jenkins · script security2 мая 2024 г.
- CVE-2026-3220248В плане
Windows Shell Spoofing Vulnerability
СредняяCVSS 4,3KEVГотовый эксплойтEPSS 5 %microsoft · windows 10 160714 апр. 2026 г.
- CVE-2025-6866843В плане
n8n Vulnerable to Arbitrary Command Execution in Pyodide based Python Code Node
КритическаяCVSS 9,9Эксплойта нетEPSS 13 %n8n · n8n26 дек. 2025 г.
- CVE-2022-3284542В плане
This issue was addressed with improved checks.
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %apple · ipados23 сент. 2022 г.
- CVE-2017-319741В плане
GIGABYTE BRIX UEFI firmware fails to securely implement BIOS write protection
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %gigabyte · gb-bsi7h-6500 firmware9 июл. 2018 г.
- CVE-2022-3597841В плане
Lua sandbox escape from mod in Minetest
КритическаяCVSS 10,0Proof of conceptEPSS 3 %minetest · minetest15 авг. 2022 г.
- CVE-2021-3283540В плане
Groovy Sandbox escape in Eclipse Keti
КритическаяCVSS 9,9Эксплойта нетEPSS 5 %eclipse · keti8 сент. 2021 г.
- CVE-2018-931840В плане
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bmw · telematics control unit firmware31 мая 2018 г.
- CVE-2018-931140В плане
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a r
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %bmw · telematics control unit firmware31 мая 2018 г.
- CVE-2020-1088740В плане
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %tp-link · ac1750 firmware25 мар. 2020 г.
- CVE-2022-3147940В плане
Remote Code Execution via command injection of the hostname
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %hidglobal · lp1501 firmware6 июн. 2022 г.
- CVE-2017-886440В плане
Client-side enforcement using JavaScript of server-side security options on the Cohu 3960HD allows an attacker to manipulate options sent to
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cohuhd · 3960hd firmware22 нояб. 2017 г.
- CVE-2019-1032840В плане
Jenkins Pipeline Remote Loader Plugin 1.4 and earlier provided a custom whitelist for script security that allowed attackers to invoke arbit
КритическаяCVSS 9,9Эксплойта нетEPSS 2 %jenkins · pipeline remote loader31 мая 2019 г.