Skip to content
Noroxi

CWE-358 · 113 records

Improperly Implemented Security Check for Standard

CVEs in this class

113 records

  • udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checks

    CriticalCVSS 9.8No exploitEPSS 13%

    linux · linux kernelApr 4, 2017

  • A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, rem

    CriticalCVSS 10.0No exploitEPSS 5%

    cisco · digital network architecture centerMay 16, 2018

  • This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.

    CriticalCVSS 9.8No exploitEPSS 6%

    samsung · galaxy s9 firmwareJun 3, 2019

  • CVE-2023-3266
    39Monitor

    A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication check

    CriticalCVSS 9.8No exploitEPSS 1%

    cyberpower · powerpanel serverAug 14, 2023

  • Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

    CriticalCVSS 9.8No exploitEPSS 1%

    navercorp · whaleOct 16, 2025

  • Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

    CriticalCVSS 9.3No exploitEPSS 1%

    mcp-tool-shop-org · backpropagateJun 17, 2026

  • ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvals

    HighCVSS 8.8No exploitEPSS 2%

    itarian · on-premiseJun 9, 2022

  • Parameter verification vulnerability in the installd module.

    CriticalCVSS 9.1No exploitEPSS 0%

    huawei · emuiAug 13, 2023

  • Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

    CriticalCVSS 9.1No exploitEPSS 0%

    navercorp · whaleDec 30, 2025

  • CVE-2019-3894
    35Monitor

    It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run th

    HighCVSS 8.8No exploitEPSS 1%

    redhat · wildflyMay 3, 2019

  • cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

    HighCVSS 8.8No exploitEPSS 1%

    cpanel · cpanelAug 1, 2019

  • CVE-2024-6101
    35Monitor

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access

    HighCVSS 8.8No exploitEPSS 1%

    google · chromeJun 19, 2024

  • A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below

    HighCVSS 8.8No exploitEPSS 1%

    fortinet · fortisandboxMar 24, 2025

  • CVE-2026-1486
    35Monitor

    Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant

    HighCVSS 8.8No exploitEPSS 0%

    red hat · red hat build of keycloak 26.4Feb 9, 2026

  • CVE-2025-3069
    35Monitor

    Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation

    HighCVSS 8.8No exploitEPSS 0%

    google · chromeApr 1, 2025

  • A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.

    HighCVSS 8.8No exploitEPSS 0%

    yokogawa electric corporation · fast/toolsFeb 9, 2026

  • In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 13%

    flexense · disk pulseJan 10, 2018

  • DVP80ES3 Improperly Implemented Security Check for Standard vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    deltaww · dvp80es3Jul 1, 2026

  • In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 9%

    flexense · vx searchJan 10, 2018

  • In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 9%

    flexense · syncbreezeJan 10, 2018

  • In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.

    HighCVSS 7.5Proof of conceptEPSS 9%

    flexense · diskbossJan 10, 2018

  • CVE-2019-3806
    32Monitor

    An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received

    HighCVSS 8.1No exploitEPSS 1%

    powerdns · recursorJan 29, 2019

  • cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

    HighCVSS 8.1No exploitEPSS 1%

    cpanel · cpanelAug 1, 2019

  • CVE-2023-2585
    32Monitor

    Keycloak: client access via device auth request spoof

    HighCVSS 8.1No exploitEPSS 1%

    redhat · single sign-onDec 21, 2023

  • Bluetooth: Out-Of-Context le_conn_rsp Handling

    HighCVSS 8.1No exploitEPSS 0%

    zephyrproject · zephyrSep 19, 2025

All vulnerability classes