CWE-693
Protection Mechanism Failure
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 49 of 49- CVE-2026-12027Critical· 9.6EPSS 0%6 h ago
Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severit
- CVE-2026-47140—EPSS 0%9 h ago
NodeVM builtin denylist bypass via process and inspector/promises allows host code execution
npm - CVE-2026-47209—EPSS 0%11 h ago
vm2's Bridge Proxy set trap ignores receiver parameter, enabling host object property injection via prototype chain
npm - CVE-2026-47135—EPSS 0%11 h ago
vm2 has a sandbox escape via unblocked cross-realm Symbol.for keys + missing bridge write-trap symbol checks
npm - CVE-2026-47139—EPSS 0%11 h ago
NodeVM network builtin exclusions bypass via internal _http_client and _http_server
npm - CVE-2026-12031High· 8.3EPSS 0%13 h ago
Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security
- CVE-2026-21510High· 8.8KEVEPSS 7%14 h ago
Microsoft Windows Shell Protection Mechanism Failure Vulnerability
- CVE-2026-21513High· 8.8KEVEPSS 28%14 h ago
Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability
- CVE-2024-21412High· 8.1KEVEPSS 94%14 h ago
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
- CVE-2026-32202Medium· 4.3KEVEXPLOITEPSS 53%14 h ago
Microsoft Windows Protection Mechanism Failure Vulnerability
- CVE-2024-38217Medium· 5.4KEVEPSS 14%14 h ago
Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability
- CVE-2024-29988High· 8.8KEVEPSS 63%14 h ago
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
- CVE-2025-0411High· 7.0KEVEPSS 47%14 h ago
7-Zip Mark of the Web Bypass Vulnerability
- CVE-2025-40536High· 8.1KEVEXPLOITEPSS 70%14 h ago
SolarWinds Web Help Desk Security Control Bypass Vulnerability
- CVE-2024-38213Medium· 6.5KEVEPSS 59%14 h ago
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2024-38226High· 7.3KEVEPSS 1%14 h ago
Microsoft Publisher Protection Mechanism Failure Vulnerability
- CVE-2025-24284High· 8.8EPSS 0%18 h ago
This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in macOS Sequoia 15.4. An app may be able to break out of its sandbox.
- CVE-2025-30431Medium· 5.5EPSS 0%18 h ago
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. A malicious app may be able to access private information.
- CVE-2026-48546High· 7.3EPSS 0%1 d ago
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.runInNewContext() sandbox context in the is
- CVE-2026-45655Medium· 5.3EPSS 0%1 d ago
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
- CVE-2026-45459Low· 3.3EPSS 0%1 d ago
Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-45588High· 7.9EPSS 0%1 d ago
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CVE-2026-45595Medium· 5.4EPSS 0%1 d ago
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
- CVE-2026-45656High· 7.8EPSS 0%2 d ago
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
- CVE-2026-4447High· 8.8EPSS 0%2 d ago
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-50564Critical· 9.9EPSS 0%2 d ago
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, Fission's Environment CRD exposes spec.runtime.podSpec and spec.builder.p
- CVE-2026-50545Critical· 9.9EPSS 0%2 d ago
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, the Environment.spec.runtime.podSpec / spec.builder.podSpec passthrough l
- CVE-2026-47656High· 7.9EPSS 0%2 d ago
Protection mechanism failure in Windows Boot Manager allows an authorized attacker to bypass a security feature locally.
- CVE-2026-48568High· 7.9EPSS 0%2 d ago
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CVE-2026-48570High· 7.9EPSS 0%2 d ago
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CVE-2026-48575High· 7.9EPSS 0%3 d ago
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CVE-2026-11234Medium· 4.3EPSS 0%3 d ago
Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11282Critical· 9.6EPSS 0%3 d ago
Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11684Low· 3.1EPSS 0%3 d ago
Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the utility process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-11695Medium· 4.3EPSS 0%3 d ago
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-11288Medium· 6.5EPSS 0%3 d ago
Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11292Medium· 4.3EPSS 0%3 d ago
Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-10950Medium· 6.5EPSS 0%4 d ago
Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-10944Medium· 6.5EPSS 0%4 d ago
Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
- CVE-2026-11170High· 8.1EPSS 0%4 d ago
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
- CVE-2026-11174Medium· 5.3EPSS 0%4 d ago
Inappropriate implementation in Site Isolation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-11260Medium· 4.3EPSS 0%4 d ago
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11264Medium· 4.3EPSS 0%4 d ago
Policy bypass in Content Security Policy in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11266Medium· 4.3EPSS 0%4 d ago
Inappropriate implementation in SafeBrowsing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass Safe Browsing via a malicious file. (Chromium security severity: Low)
- CVE-2026-11263Medium· 6.5EPSS 0%4 d ago
Insufficient policy enforcement in WebAuthentication in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security
- CVE-2026-11206Medium· 6.5EPSS 0%7 d ago
Insufficient policy enforcement in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2026-11247Low· 3.1EPSS 0%7 d ago
Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11248High· 8.8EPSS 0%7 d ago
Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-11219Medium· 4.3EPSS 0%7 d ago
Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.