Skip to main content

CWE archive

CWE-693 CVEs

Programmatic archive

639 CVEs tagged with CWE-69393 Critical, 224 High, 280 Medium, 42 Low, 0 Unrated.

CVE-2025-65319

Published Dec 16, 2025

When using the attachment interaction functionality, Blue Mail 1.140.103 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-65318

Published Dec 16, 2025

When using the attachment interaction functionality, Canary Mail 5.1.40 and below saves documents to a file system without a Mark-of-the-Web tag, which allows attackers to bypass…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-36938

Published Dec 11, 2025

In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-67460

Published Dec 10, 2025

Protection Mechanism Failure of Software Downgrade in Zoom Rooms for Windows before 6.6.0 may allow an unauthenticated user to conduct an escalation of privilege via local access.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-67485

Published Dec 10, 2025

mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom security policies. Versions 0.3 and below allow attackers to…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-34413

Published Dec 9, 2025

Legality WHISTLEBLOWING by DigitalPA contains a protection mechanism failure in which critical HTTP security headers are not emitted by default. Affected deployments omit Content-…

CVSS 7.1 · High

CVE-2025-66204

Published Dec 9, 2025

WBCE CMS is a content management system. Version 1.6.4 contains a brute-force protection bypass where an attacker can indefinitely reset the counter by modifying `X-Forwarded-For`…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48626

Published Dec 8, 2025

In multiple locations, there is a possible way to launch an application from the background due to a precondition check failure. This could lead to remote escalation of privilege…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-66479

Published Dec 4, 2025

Anthropic Sandbox Runtime is a lightweight sandboxing tool for enforcing filesystem and network restrictions on arbitrary processes at the OS level, without requiring a container.…

CVSS 1.8 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-64763

Published Dec 3, 2025

Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is configured in TCP proxy mode to handle CONNECT requests, it…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-29864

Published Dec 3, 2025

Protection Mechanism Failure vulnerability in ESTsoft ALZip on Windows allows SmartScreen bypass.This issue affects ALZip: from 12.01 before 12.29.

CVSS 6.2 · Medium

CVE-2025-65100

Published Nov 19, 2025

Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT_SNAPSHOT_DATE alone does not set the correct timestamp val…

CVSS 6.9 · Medium

CVE-2025-11260

Published Nov 13, 2025

The WP Headless CMS Framework plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.15. This is due to the plugin only checking…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-62453

Published Nov 11, 2025

Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to bypass a security feature locally.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-35968

Published Nov 11, 2025

Protection mechanism failure in the UEFI firmware for the Slim Bootloader within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged us…

CVSS 7.1 · High

CVE-2025-26402

Published Nov 11, 2025

Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated us…

CVSS 6.8 · Medium

CVE-2025-24848

Published Nov 11, 2025

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24834

Published Nov 11, 2025

Protection mechanism failure for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged s…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-10905

Published Nov 11, 2025

Collision in MiniFilter driver in Avast Software Avast Free Antivirus  before 25.9  on Windows allows a local attacker with administrative privileges to disable real-time protecti…

CVSS 4.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2025-12909

Published Nov 8, 2025

Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cross-origin data via Devtools. (Chromium security severity:…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12906

Published Nov 8, 2025

Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security se…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-60711

Published Oct 31, 2025

Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-12094

Published Oct 31, 2025

The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to IP Header Spoofing in all versions up to, and including, 1…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
23.9
Showing 276-300 of 639 CVEsPage 12 of 26