CWE-693
CVEs classified under CWE-693, newest first.
276 CVEsRSS
CVE-2026-70601High· 7.5Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.5, apps that expose Promise-returning functions to web content via contextBridge may…
CVE-2026-53949Medium· 5.3Ghost Content API filter bypass reveals private fields
Ghost Content API filter bypass reveals private fields
CVE-2026-17677High· 8.8Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17676Critical· 9.6Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page
Inappropriate implementation in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium securi…
CVE-2026-17669Critical· 9.6Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
CVE-2026-17764Medium· 6.5Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page
Inappropriate implementation in FedCM in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
CVE-2026-67427High· 8.6Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
Flyto2 Core: ${env.VAR} interpolation reads any env secret despite env.get being denylisted
GHSA-xvg2-cgv6-6h7vHighnetfoil: Incorrect block responses could lead to localhost traffic
netfoil: Incorrect block responses could lead to localhost traffic
GHSA-qqc3-94qv-7fw3MediumHubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
Hubuum client library (Rust): Configured custom transports may be bypassed, exposing credentials and network traffic
CVE-2026-59223Medium· 4.3Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
Open WebUI: `WEB_FETCH_FILTER_LIST` host allow/block filter bypassable via URL path and non-label-boundary matching
CVE-2026-59207Highn8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
n8n: "Allowed HTTP Request Domains" Restriction Bypass via AI Agents MCP Connector
GHSA-c2j3-45gr-mqc4LowDOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
DOMPurify: `CUSTOM_ELEMENT_HANDLING` bypasses `afterSanitizeElements` for allowed custom elements.
CVE-2026-50646High· 7.8.NET Framework Remote Code Execution Vulnerability
Protection mechanism failure in .NET Framework allows an unauthorized attacker to execute code locally.
CVE-2026-50661Medium· 6.1Windows BitLocker Security Feature Bypass Vulnerability
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
CVE-2026-47305High· 7.8Visual Studio Remote Code Execution Vulnerability
Protection mechanism failure in Visual Studio allows an unauthorized attacker to execute code locally.
CVE-2026-34348Medium· 6.5PoCProtection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
Protection mechanism failure in Windows Event Logging Service allows an authorized attacker to disclose information over a network.
CVE-2026-15528Low· 3.3A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1
A vulnerability was found in lamaalrajih kicad-mcp up to 3.3.1. This issue affects some unknown processing of the file kicad_mcp/utils/path_validator.py. Performing a manipulation of the argument project_path/schematic_path results in pr…
GHSA-xrmc-c5cg-rv7xHigh· 8.8SafeInstall agent guard shell parsing can miss raw package execution
SafeInstall agent guard shell parsing can miss raw package execution
CVE-2026-59854Medium· 4.9SiYuan is an open-source personal knowledge management system
SiYuan is an open-source personal knowledge management system. Prior to 3.7.1, POST /api/file/globalCopyFiles accepts attacker-supplied absolute source paths and relies on util.IsSensitivePath in kernel/util/path.go, whose denylist misse…
CVE-2026-0278NoneMultiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
GHSA-59qp-cfj3-rp64Mediumnetfoil has a domain name filter bypass via multiple questions
netfoil has a domain name filter bypass via multiple questions
GHSA-fqf6-gxhh-2xhwHighuutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
uutils coreutils: cp/install/mv/ln --suffix alone does not enable backup mode (silent data loss vs GNU)
CVE-2026-35349Medium· 6.7rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
rm: --preserve-root bypassed via a symlink to / (string check instead of dev/inode)
CVE-2026-35363Medium· 5.6rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
rm: 'rm -rf ./' (and ./// variants) silently deletes current directory contents, bypassing dot protection
CVE-2026-14535High· 8.8In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as un…
In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(node) on every import node it inspects, regardless of whether the import is flagged as un…
CVE-2026-14625Medium· 6.3A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2
A security flaw has been discovered in NousResearch hermes-agent up to 0.15.2. The affected element is the function shell.exec of the file tui_gateway/server.py. The manipulation results in protection mechanism failure. It is possible to…
CVE-2025-71373High· 8.1picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks
picklescan before 0.0.33 fails to detect operator.methodcaller function calls in pickle files, allowing attackers to bypass security checks. Remote attackers can craft malicious pickle payloads using operator.methodcaller that execute ar…
CVE-2026-14409High· 7.5Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium sec…
CVE-2026-49981HighTwig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
Twig: Sandbox filter, tag and function allow-list bypass when sandbox state changes between renders for a cached `Template`
CVE-2026-13951High· 8.3Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page
Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severit…