CWE-693: CWE-693

132
Total CVEs
23
Critical
62
High
7.5
Avg CVSS
4
In CISA KEV

Yearly Trend

2026
13
2025
76
2024
30
2023
9
2022
3

Top Affected Vendors

1 Microsoft 25
2 Google 23
3 Apple 11
4 Mozilla 4
5 Mattermost 4
6 Cisco 3
7 Intel 3
8 Fedoraproject 2
9 Dell 2
10 Jenkins 2

All CWE-693 CVEs (132)

CVE-2025-48546
7.8

This vulnerability allows malicious apps to launch background activities without proper permission checks, enabling local privilege escalation on Andr...

Sep 4, 2025
CVE-2025-48522
7.8

This vulnerability allows a malicious app to retain Content Delivery Manager (CDM) association due to a logic error in Android's AssociationRequest.ja...

Sep 4, 2025
CVE-2025-32331
7.8

This vulnerability allows bypassing Android's app pinning feature due to a logic error in the KeyguardService. Attackers can escalate privileges local...

Sep 4, 2025
CVE-2025-0089
7.8

This CVE describes a logic error in Android's Launcher app that allows local privilege escalation without user interaction. An attacker could hijack t...

Sep 4, 2025
CVE-2025-26458
7.8

This vulnerability allows malicious apps to launch background activities without user interaction due to a logic error in Android's LocationProviderMa...

Sep 4, 2025
CVE-2025-36898
7.8

CVE-2025-36898 is a local privilege escalation vulnerability in Android's Pixel devices that allows attackers to gain elevated privileges without user...

Sep 4, 2025
CVE-2025-22433
7.8

This vulnerability allows an attacker to bypass cross-profile intent filters in Android's Work Profile feature, enabling local privilege escalation wi...

Sep 2, 2025
CVE-2024-49720
7.8

This vulnerability allows local attackers to override Android's location permission settings due to a logic error in Permissions.java. It enables loca...

Sep 2, 2025
CVE-2025-47159
7.8

A protection mechanism failure in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally. Thi...

Jul 8, 2025
CVE-2025-24061
7.8

This vulnerability allows local attackers to bypass Windows Mark of the Web (MOTW) security protections, which normally warn users about files downloa...

Mar 11, 2025
CVE-2024-8811
7.8

This vulnerability allows attackers to bypass WinZip's Mark-of-the-Web protection by tricking users into opening malicious archive files. When exploit...

Nov 22, 2024
CVE-2024-38070
7.8

This vulnerability allows attackers to bypass Windows LockDown Policy (WLDP) security features, potentially enabling execution of untrusted code. It a...

Jul 9, 2024
CVE-2022-48611
7.8

CVE-2022-48611 is a local privilege escalation vulnerability in iTunes for Windows. A local attacker can exploit a logic issue to gain elevated privil...

Apr 26, 2024
CVE-2024-28920
7.8

CVE-2024-28920 is a Secure Boot security feature bypass vulnerability that allows attackers to bypass Secure Boot protections on affected systems. Thi...

Apr 9, 2024
CVE-2024-0014
7.8

This vulnerability in Android's update system allows attackers to trigger malicious configuration updates without user interaction, leading to local p...

Feb 16, 2024
CVE-2023-21024
7.8

This Android vulnerability allows local privilege escalation without user interaction due to a logic error in the FallbackHome.java component. It dela...

Mar 24, 2023
CVE-2022-26774
7.8

CVE-2022-26774 is a local privilege escalation vulnerability in iTunes for Windows. A local attacker can exploit this logic issue to gain elevated sys...

May 26, 2022
CVE-2025-46358
7.7

Emerson ValveLink products lack proper protection mechanisms against directed attacks, allowing attackers to potentially compromise industrial control...

Jul 11, 2025
CVE-2024-43584
7.7

This vulnerability allows attackers to bypass security features in the Windows Scripting Engine, potentially executing malicious scripts with elevated...

Oct 8, 2024
CVE-2022-22152
7.7

This CVE-2022-22152 is a protection mechanism failure in Juniper Contrail Service Orchestration's REST API that allows one tenant to view another tena...

Jan 19, 2022
CVE-2025-46290
7.5

A logic vulnerability in macOS allows remote attackers to cause denial-of-service conditions. This affects macOS Sequoia before 15.7.4 and macOS Sonom...

Feb 11, 2026
CVE-2025-47984
7.5

This vulnerability in Windows GDI (Graphics Device Interface) allows an unauthorized attacker to remotely access and disclose sensitive information fr...

Jul 8, 2025
CVE-2025-33050
7.5

A protection mechanism failure in Windows DHCP Server allows unauthorized attackers to cause denial of service over a network. This affects organizati...

Jun 10, 2025
CVE-2024-0101
7.5

This vulnerability in NVIDIA networking products allows attackers to cause denial of service through improper ipfilter definitions. Attackers can expl...

Aug 8, 2024
CVE-2024-31142
7.5

This CVE-2024-31142 vulnerability involves a logical error in Xen's XSA-407 mitigation for Branch Type Confusion, causing the protection to not apply ...

May 16, 2024
CVE-2024-0804
7.5

This vulnerability allows attackers to bypass Chrome's cross-origin security policies on iOS devices, enabling them to read data from other websites v...

Jan 24, 2024
CVE-2023-35352
7.5

This vulnerability allows attackers to bypass security features in Windows Remote Desktop, potentially gaining unauthorized access to systems. It affe...

Jul 11, 2023
CVE-2025-26443
7.3

This vulnerability in Android's ManagedProvisioning component allows attackers to bypass the 'Install from unknown sources' restriction through a logi...

Sep 4, 2025
CVE-2025-22427
7.3

This vulnerability allows an attacker with physical access to an Android device to grant notification access above the lock screen through a logic err...

Sep 2, 2025
CVE-2024-38226
7.3

This vulnerability allows attackers to bypass security features in Microsoft Publisher, potentially enabling them to execute malicious code or gain un...

Sep 10, 2024
CVE-2023-32493
7.3

Dell PowerScale OneFS versions 9.5.0.x contain a protection mechanism bypass vulnerability that allows unprivileged remote attackers to potentially ex...

Aug 16, 2023
CVE-2024-28248
7.2

CVE-2024-28248 is a security vulnerability in Cilium's HTTP policy enforcement where HTTP traffic that should be blocked according to configured polic...

Mar 18, 2024
CVE-2025-21346
7.1

This CVE describes a security feature bypass vulnerability in Microsoft Office that could allow attackers to circumvent built-in security protections....

Jan 14, 2025
CVE-2025-0411
KEV EPSS 33.8% 7.0

This vulnerability allows attackers to bypass Windows' Mark-of-the-Web security feature when extracting files with 7-Zip. Attackers can craft maliciou...

Jan 25, 2025
CVE-2023-3089
7.0

This CVE describes a compliance issue in Red Hat OpenShift Container Platform where, when FIPS mode is enabled, not all cryptographic modules used are...

Jul 5, 2023
CVE-2025-14304
6.8

This vulnerability allows unauthenticated physical attackers with DMA-capable PCIe devices to read and write arbitrary physical memory on affected ASR...

Dec 17, 2025
CVE-2025-14302
6.8

This vulnerability allows unauthenticated physical attackers with DMA-capable PCIe devices to read and write arbitrary physical memory on affected GIG...

Dec 17, 2025
CVE-2025-14303
6.8

This vulnerability allows unauthenticated physical attackers with DMA-capable PCIe devices to read and write arbitrary physical memory on affected MSI...

Dec 17, 2025
CVE-2025-8656
6.8

This vulnerability allows physically present attackers to downgrade the software on Kenwood DMX958XR devices without authentication, potentially enabl...

Aug 6, 2025
CVE-2025-26637
6.8

This CVE describes a protection mechanism failure in Windows BitLocker that allows unauthorized attackers with physical access to bypass security feat...

Apr 8, 2025
CVE-2026-24868
6.5

This CVE describes a mitigation bypass vulnerability in Firefox's Privacy: Anti-Tracking component that could allow attackers to circumvent privacy pr...

Jan 27, 2026
CVE-2025-26402
6.5

This vulnerability in Intel NPU drivers allows unprivileged user applications to cause a denial of service via local access. It affects systems with v...

Nov 11, 2025
CVE-2025-24834
6.5

An information disclosure vulnerability in Intel CIP software allows unprivileged local attackers to access sensitive data from user applications. Thi...

Nov 11, 2025
CVE-2025-55886
6.5

An authenticated attacker can manipulate the fe_uid parameter in ARD's payment history API to view other users' payment records without authorization....

Sep 22, 2025
CVE-2025-24835
6.5

A protection mechanism failure in Intel Graphics Driver for Arc B-Series graphics allows authenticated local users to potentially cause denial of serv...

Aug 12, 2025
CVE-2024-11734
6.5

A denial-of-service vulnerability in Keycloak allows administrative users with realm settings modification privileges to disrupt service by injecting ...

Jan 14, 2025
CVE-2024-43487
6.5

This vulnerability allows attackers to bypass Windows' Mark of the Web (MoTW) security feature, which warns users when opening files downloaded from t...

Sep 10, 2024
CVE-2024-24983
6.5

A protection mechanism failure in Intel E810 Series Ethernet controller firmware allows unauthenticated attackers to potentially cause denial of servi...

Aug 14, 2024
CVE-2025-35968
6.4

A UEFI firmware vulnerability in Slim Bootloader allows local attackers to escalate privileges by exploiting protection mechanism failures. This affec...

Nov 11, 2025
CVE-2025-24848
6.3

This vulnerability in Intel CIP software allows local attackers to escalate privileges from unprivileged to privileged access. It affects systems runn...

Nov 11, 2025

About CWE-693 (CWE-693)

Our database tracks 132 CVEs classified as CWE-693, with 23 rated critical and 62 rated high severity. The average CVSS score for CWE-693 vulnerabilities is 7.5.

External reference: View CWE-693 on MITRE CWE →

Monitor CWE-693 Vulnerabilities

Get alerted when new CWE-693 CVEs affect your infrastructure.

Start Monitoring Free