Threats Tagged 'cwe-693'
View all threats tagged with 'cwe-693'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-693'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-19152: Inappropriate implementation in Google ChromeCVE-2026-19152 0 Insufficient policy enforcement in Navigation in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:48 UTC Added: 08/07/2026, 05:56:49 UTC |
CVE-2026-19168: Inappropriate implementation in Google ChromeCVE-2026-19168 0 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:42 UTC Added: 08/07/2026, 05:56:40 UTC |
CVE-2026-19150: Inappropriate implementation in Google ChromeCVE-2026-19150 0 Inappropriate implementation in V8 in Google Chrome prior to 151.0.7922.109 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 08/06/2026, 20:33:47 UTC Added: 08/07/2026, 05:56:40 UTC |
CVE-2026-13342: CWE-693 Protection Mechanism Failure in Security OptimizerCVE-2026-13342 0 The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-based login restriction feature, allowing the restriction to be bypassed so that unauthenticated requests from non-allowlisted IP addresses can reach and use the login form, defeating the access control the administrator configured. Join the discussion | CVE Database V5 | 08/07/2026, 00:31:14 UTC Added: 08/06/2026, 22:13:07 UTC |
CVE-2025-15039: CWE-693: Protection Mechanism Failure in WSO2 WSO2 Identity ServerCVE-2025-15039 0 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a specific multi-step pattern involving certain authenticators is configured. This allows an attacker to bypass intermediate authentication challenges by exploiting how the script handles callbacks and re-execution of authentication steps. Successful exploitation allows a malicious actor to gain unauthorized access to a targeted user account. This vulnerability can only be exploited when all of the following conditions are met: the application login flow contains a specific secondary authenticator, the Conditional Authentication script is configured with particular event callbacks and re-executes an authentication step, the targeted user has one of the impacted authenticators enrolled, and the attacker successfully completes any preceding authentication steps. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:23 UTC Added: 08/06/2026, 08:11:46 UTC |
CVE-2024-6832: CWE-693: Protection Mechanism Failure in WSO2 WSO2 Enterprise IntegratorCVE-2024-6832 0 The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores. When the account locking mechanism is bypassed due to the inaccessibility of secondary user stores, users in accessible user stores are left vulnerable to brute force attacks. A malicious actor can exploit this by attempting numerous invalid password combinations against a user account without the expected account lockout consequence. Join the discussion | CVE Database V5 | 08/06/2026, 07:32:59 UTC Added: 08/06/2026, 08:11:46 UTC |
Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted… (CVE-2026-17764)CVE-2026-17764 0 Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) Join the discussion | GCVE Database | 07/30/2026, 03:31:12 UTC Added: 08/01/2026, 08:14:09 UTC |
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a… (CVE-2026-17669)CVE-2026-17669 0 Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 07/30/2026, 00:18:48 UTC Added: 07/30/2026, 05:46:09 UTC |
Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer… (CVE-2026-17659)CVE-2026-17659 0 Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 07/30/2026, 00:18:45 UTC Added: 07/30/2026, 05:46:09 UTC |
Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer… (CVE-2026-17710)CVE-2026-17710 0 Inappropriate implementation in MHTML in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) Join the discussion | GCVE Database | 07/30/2026, 00:19:00 UTC Added: 07/30/2026, 05:46:06 UTC |
Showing 1 to 10 of 49 results