CWE-358— Improperly Implemented Security Check for Standard
79 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-358page 1 of 2
- CVE-2016-10825HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
- CVE-2016-10834HIGHCVSS 8.8EG 8.82019-08-01
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
- CVE-2016-8614MEDIUMCVSS 6.32018-07-31
A flaw was found in Ansible before version 2.2.0. The apt_key module does not properly verify key fingerprints, allowing remote adversary to create an OpenPGP key which matches the short key ID and inject this key instead of the correct ke…
- CVE-2016-8635MEDIUMCVSS 5.32018-08-01
It was found that Diffie Hellman Client key exchange handling in NSS 3.21.x was vulnerable to small subgroup confinement attack. An attacker could use this flaw to recover private keys by confining the client DH key to small subgroup of th…
- CVE-2017-15091HIGHCVSS 7.12018-01-23
An issue has been found in the API component of PowerDNS Authoritative 4.x up to and including 4.0.4 and 3.x up to and including 3.4.11, where some operations that have an impact on the state of the server are still allowed even though the…
- CVE-2017-15105MEDIUMCVSS 5.32018-01-23
A flaw was found in the way unbound before 1.6.8 validated wildcard-synthesized NSEC records. An improperly validated wildcard NSEC record could be used to prove the non-existence (NXDOMAIN answer) of an existing wildcard record, or trick …
- CVE-2017-15107HIGHCVSS 7.52018-01-23
A vulnerability was found in the implementation of DNSSEC in Dnsmasq up to and including 2.78. Wildcard synthesized NSEC records could be improperly interpreted to prove the non-existence of hostnames that actually exist.
- CVE-2017-15662HIGHCVSS 7.5EG 7.52018-01-10
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9123.
- CVE-2017-15663HIGHCVSS 7.5EG 7.52018-01-10
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9120.
- CVE-2017-15664HIGHCVSS 7.5EG 7.52018-01-10
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9121.
- CVE-2017-15665HIGHCVSS 7.5EG 7.52018-01-10
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 8094.
- CVE-2017-15706MEDIUMCVSS 5.32018-01-31
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify w…
- CVE-2017-2604MEDIUMCVSS 4.32018-05-15
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).
- CVE-2017-2611MEDIUMCVSS 4.32018-05-08
Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read ac…
- CVE-2017-2612MEDIUMCVSS 5.42018-05-15
In Jenkins before versions 2.44, 2.32.2 low privilege users were able to override JDK download credentials (SECURITY-392), resulting in future builds possibly failing to download a JDK.
- CVE-2018-0268CRITICALCVSS 10.0EG 10.02018-05-17
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an…
- CVE-2018-1243HIGHCVSS 7.52018-07-02
Dell EMC iDRAC6, versions prior to 2.91, iDRAC7/iDRAC8, versions prior to 2.60.60.60 and iDRAC9, versions prior to 3.21.21.21, contain a weak CGI session ID vulnerability. The sessions invoked via CGI binaries use 96-bit numeric-only sessi…
- CVE-2018-1270CRITICALCVSS 9.82018-04-06
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2018-1275CRITICALCVSS 9.82018-04-11
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2018-16857HIGHCVSS 7.42018-11-28
Samba from version 4.9.0 and before version 4.9.3 that have AD DC configurations watching for bad passwords (to restrict brute forcing of passwords) in a window of more than 3 minutes may not watch for bad passwords at all. The primary ris…
- CVE-2018-16860HIGHCVSS 7.5EG 7.52019-07-31
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to i…
- CVE-2018-20934MEDIUMCVSS 6.5EG 6.52019-08-01
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
- CVE-2018-7685HIGHCVSS 7.82018-08-31
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malici…
- CVE-2019-14823HIGHCVSS 7.4EG 7.42019-10-14
A flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it implicitly trusted the root certificate of a certificate chain. Applications using this policy may not p…
- CVE-2019-3806HIGHCVSS 8.1EG 8.12019-01-29
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced us…
- CVE-2019-3894HIGHCVSS 8.82019-05-03
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. Thi…
- CVE-2019-6742CRITICALCVSS 9.82019-06-03
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hand…
- CVE-2020-10743MEDIUMCVSS 4.3EG 4.32021-06-02
It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercept and manipulate requests. This flaw allows an attacker to trick a user into performing arbitrary…
- CVE-2020-1728MEDIUMCVSS 4.8EG 4.82020-04-06
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses. This does not directly lead to a security issue, ye…
- CVE-2020-1761MEDIUMCVSS 6.1EG 6.12021-05-27
A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaw to get the access token via physical access, or an XSS attack on the victim's browser. This flaw …
- CVE-2020-25684LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does no…
- CVE-2020-25685LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due …
- CVE-2020-25686LOWCVSS 3.7EG 3.72021-01-20
A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstr…
- CVE-2020-7251MEDIUMCVSS 5.0EG 5.02020-02-14
Improper access control vulnerability in Configuration Tool in McAfee Mcafee Endpoint Security (ENS) Prior to 10.6.1 February 2020 Update allows local users to disable security features via unauthorised use of the configuration tool from o…
- CVE-2020-8352LOWCVSS 2.4EG 2.42020-11-11
In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.
- CVE-2021-21387HIGHCVSS 8.1EG 8.12021-03-19
Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part of the secret identi…
- CVE-2021-26328MEDIUMCVSS 4.4EG 4.42023-01-11
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
- CVE-2021-31375HIGHCVSS 7.2EG 5.32021-10-19
An Improper Input Validation vulnerability in routing process daemon (RPD) of Juniper Networks Junos OS devices configured with BGP origin validation using Resource Public Key Infrastructure (RPKI), allows an attacker to send a specific BG…
- CVE-2021-3448MEDIUMCVSS 4.0EG 4.02021-04-08
A flaw was found in dnsmasq in versions before 2.85. When configured to use a specific server for a given network interface, dnsmasq uses a fixed port while forwarding queries. An attacker on the network, able to find the outgoing port use…
- CVE-2021-34790MEDIUMCVSS 4.7EG 5.32021-10-27
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticate…
- CVE-2021-34791MEDIUMCVSS 4.7EG 5.32021-10-27
Multiple vulnerabilities in the Application Level Gateway (ALG) for the Network Address Translation (NAT) feature of Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticate…
- CVE-2021-42017MEDIUMCVSS 5.9EG 5.92022-03-08
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i801, RUGGEDCOM i802, RUGGEDCOM i803, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM M969, RUGGEDCOM M969F, RUGGEDCOM RMC30, RUGGEDCOM RMC838…
- CVE-2022-22156MEDIUMCVSS 6.5EG 6.52022-01-19
An Improper Certificate Validation weakness in the Juniper Networks Junos OS allows an attacker to perform Person-in-the-Middle (PitM) attacks when a system script is fetched from a remote source at a specified HTTPS URL, which may comprom…
- CVE-2022-2324HIGHCVSS 7.5EG 7.52022-07-29
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions
- CVE-2022-25152CRITICALCVSS 9.9EG 8.82022-06-09
The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any …
- CVE-2022-27219MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 443. This could aid attackers by making the s…
- CVE-2022-27220MEDIUMCVSS 4.3EG 4.32022-06-14
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP security headers in the web server configured on port 6220. This could aid attackers by making the …
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-38732HIGHCVSS 7.5EG 7.52022-09-29
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented.
- CVE-2023-22393HIGHCVSS 7.5EG 7.52023-01-13
An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with inv…
Map vulnerabilities like CWE-358 to your infrastructure
EchelonGraph correlates every CVE — across CWE-358 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →