CWE-358— Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.— MITRE CWE catalog
138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-358page 1 of 3
- CVE-2024-7965CRITICALCVSS 8.8EG 9.0⚠ KEV2024-08-21
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2018-0268CRITICALCVSS 10.0EG 10.02018-05-17
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an…
- CVE-2022-25152CRITICALCVSS 9.9EG 9.92022-06-09
The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any …
- CVE-2026-96760CRITICALCVSS 9.8EG 9.82026-09-28
Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json() method accepts a JSON Serialization JWS object and returns the payload as successfully verified without checking for…
- CVE-2026-50628CRITICALCVSS 9.8EG 9.82026-06-12
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security che…
- CVE-2025-66603CRITICALCVSS 9.8EG 9.82026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks. The affected products a…
- CVE-2025-62583CRITICALCVSS 9.8EG 9.82025-10-16
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
- CVE-2023-4501CRITICALCVSS 9.8EG 9.82023-09-12
User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versio…
- CVE-2023-3266CRITICALCVSS 9.8EG 9.82023-08-14
A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to…
- CVE-2019-6742CRITICALCVSS 9.8EG 9.82019-06-03
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hand…
- CVE-2018-1275CRITICALCVSS 9.8EG 9.82018-04-11
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2018-1270CRITICALCVSS 9.8EG 9.82018-04-06
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging m…
- CVE-2016-10229CRITICALCVSS 9.8EG 9.82017-04-04
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.
- CVE-2024-6995CRITICALCVSS 4.7EG 9.82024-08-06
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to spoof the contents of the Omnibox (URL bar) via a crafted HTM…
- CVE-2024-7003CRITICALCVSS 4.3EG 9.82024-08-06
Inappropriate implementation in FedCM in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
- CVE-2024-3845CRITICALCVSS 4.3EG 9.82024-04-17
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
- CVE-2026-48797CRITICALCVSS 9.3EG 9.32026-06-17
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training …
- CVE-2025-69234CRITICALCVSS 9.1EG 9.12025-12-30
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
- CVE-2023-39403CRITICALCVSS 9.1EG 9.12023-08-13
Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.
- CVE-2026-44513HIGHCVSS 8.8EG 8.82026-05-14
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omitt…
- CVE-2026-1486HIGHCVSS 8.8EG 8.82026-02-09
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verify if an Identity Provider (IdP) is enabled before issuing tokens. The issuer lookup mechanism (lookupIdentityProviderFr…
- CVE-2025-66600HIGHCVSS 8.8EG 8.82026-02-09
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications …
- CVE-2025-3069HIGHCVSS 8.8EG 8.82025-04-02
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
- CVE-2024-6773HIGHCVSS 8.8EG 8.82024-07-16
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-6772HIGHCVSS 8.8EG 8.82024-07-16
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-6101HIGHCVSS 8.8EG 8.82024-06-20
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-2174HIGHCVSS 8.8EG 8.82024-03-06
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
- CVE-2016-10834HIGHCVSS 8.8EG 8.82019-08-01
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
- CVE-2019-3894HIGHCVSS 8.8EG 8.82019-05-03
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run the thread as. These threads do not necessarily terminate if the keep alive time has not expired. Thi…
- CVE-2026-12577HIGHCVSS 8.7EG 8.72026-07-01
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
- CVE-2023-28601HIGHCVSS 8.3EG 8.32023-06-13
Zoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. A malicious user may alter protected Zoom Client memory buffer potentially causing integrity issues…
- CVE-2021-21387HIGHCVSS 8.1EG 8.12021-03-19
Wrongthink peer-to-peer, end-to-end encrypted messenger with PeerJS and Axolotl ratchet. In wrongthink from version 2.0.0 and before 2.3.0 there was a set of vulnerabilities causing inadequate encryption strength. Part of the secret identi…
- CVE-2016-10825HIGHCVSS 8.1EG 8.12019-08-01
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
- CVE-2019-3806HIGHCVSS 8.1EG 8.12019-01-29
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received over TCP in some specific combination of settings, possibly bypassing security policies enforced us…
- CVE-2024-27842HIGHCVSS 7.8EG 8.12024-05-14
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.5. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2026-49783HIGHCVSS 7.8EG 7.82026-07-14
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
- CVE-2024-40650HIGHCVSS 7.8EG 7.82024-09-11
In wifi_item_edit_content of styles.xml , there is a possible FRP bypass due to Missing check for FRP state. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2024-25545HIGHCVSS 7.8EG 7.82024-04-12
An issue in Weave Weave Desktop v.7.78.10 allows a local attacker to execute arbitrary code via a crafted script to the nwjs framework component.
- CVE-2018-7685HIGHCVSS 7.8EG 7.82018-08-31
The decoupled download and installation steps in libzypp before 17.5.0 could lead to a corrupted RPM being left in the cache, where a later call would not display the corrupted RPM warning and allow installation, a problem caused by malici…
- CVE-2026-40597HIGHCVSS 7.6EG 7.62026-05-22
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS / HTML injection vulnerability, an attacker can bypass the Content Security Policy's script-src directive by uploading …
- CVE-2026-45109HIGHCVSS 7.5EG 7.52026-05-13
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was found that the fix addressing CVE-2026-44575 did not apply to middleware.ts with Turbopack. This vulnerability is fixed…
- CVE-2026-2645HIGHCVSS 7.5EG 7.52026-03-19
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could incorrectly accept the CertificateVerify message before the ClientKeyExchange message had been received. This issue aff…
- CVE-2025-62585HIGHCVSS 7.5EG 7.52025-10-16
Whale browser before 4.33.325.17 allows an attacker to bypass the Content Security Policy via a specific scheme in a dual-tab environment.
- CVE-2025-59147HIGHCVSS 7.5EG 7.52025-10-01
Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sen…
- CVE-2023-40445HIGHCVSS 7.5EG 7.52023-10-25
The issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17.1. A device may persistently fail to lock.
- CVE-2023-22393HIGHCVSS 7.5EG 7.52023-01-13
An Improper Check for Unusual or Exceptional Conditions vulnerability in BGP route processing of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to cause Routing Protocol Daemon (RPD) crash by sending a BGP route with inv…
- CVE-2022-3691HIGHCVSS 7.5EG 7.52022-11-21
The DeepL Pro API translation plugin WordPress plugin before 1.7.5 discloses sensitive information (including the DeepL API key) in files that are publicly accessible to an external, unauthenticated visitor.
- CVE-2022-38732HIGHCVSS 7.5EG 7.52022-09-29
SnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that otherwise would be prevented.
- CVE-2022-2324HIGHCVSS 7.5EG 7.52022-07-29
Improperly Implemented Security Check vulnerability in the SonicWall Hosted Email Security leads to bypass of Capture ATP security service in the appliance. This vulnerability impacts 10.0.17.7319 and earlier versions
- CVE-2018-16860HIGHCVSS 7.5EG 7.52019-07-31
A flaw was found in samba's Heimdal KDC implementation, versions 4.8.x up to, excluding 4.8.12, 4.9.x up to, excluding 4.9.8 and 4.10.x up to, excluding 4.10.3, when used in AD DC mode. A man in the middle attacker could use this flaw to i…
Map vulnerabilities like CWE-358 to your infrastructure
EchelonGraph correlates every CVE — across CWE-358 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →