The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Volume of CVEs assigned to CWE-693 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
639 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-40536CRITICAL SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could allow an unauthenticated attacker to gain access to certain | Jan 28, 2026 | 9.8 | 98 | YES | YES |
CVE-2013-2465CRITICAL Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and Ope | Jun 18, 2013 | 9.8 | 98 | YES | YES |
CVE-2013-0431MEDIUM Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the | Jan 31, 2013 | 5.3 | 97 | YES | YES |
CVE-2019-1003030CRITICAL A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allo | Mar 8, 2019 | 9.9 | 96 | YES | YES |
CVE-2024-21412HIGH Internet Shortcut Files Security Feature Bypass Vulnerability | Feb 13, 2024 | 8.1 | 95 | YES | NO |
CVE-2026-32202MEDIUM Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network. | Apr 14, 2026 | 4.3 | 93 | YES | YES |
CVE-2025-0411HIGH 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User i | Jan 25, 2025 | 7.0 | 89 | YES | NO |
CVE-2024-29988HIGH SmartScreen Prompt Security Feature Bypass Vulnerability | Apr 9, 2024 | 8.8 | 85 | YES | NO |
CVE-2026-21510HIGH Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | 8.8 | 84 | YES | NO |
CVE-2026-21513HIGH Protection mechanism failure in MSHTML Framework allows an unauthorized attacker to bypass a security feature over a network. | Feb 10, 2026 | 8.8 | 81 | YES | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.