CWE-358 · 113 records
Improperly Implemented Security Check for Standard
CVEs in this class
113 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2016-10229No exploit | udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checkslinux · linux kernel · CWE-358 | Critical9.8 | — | 12.8% | Apr 4, 2017 |
42Plan | CVE-2018-0268No exploit | A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remcisco · digital network architecture center · CWE-358 | Critical10.0 | — | 5.0% | May 16, 2018 |
41Plan | CVE-2019-6742No exploit | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.samsung · galaxy s9 firmware · CWE-358 | Critical9.8 | — | 5.9% | Jun 3, 2019 |
39Monitor | CVE-2023-3266No exploit | A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checkcyberpower · powerpanel server · CWE-358 | Critical9.8 | — | 0.9% | Aug 14, 2023 |
39Monitor | CVE-2025-62583No exploit | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.navercorp · whale · CWE-358 | Critical9.8 | — | 0.5% | Oct 16, 2025 |
37Monitor | CVE-2026-48797No exploit | Backpropagate: backprop ui --auth and backprop ui --share do not enforce authenticationmcp-tool-shop-org · backpropagate · CWE-358 | Critical9.3 | — | 0.6% | Jun 17, 2026 |
36Monitor | CVE-2022-25152No exploit | ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvalsitarian · on-premise · CWE-358 | High8.8 | — | 1.8% | Jun 9, 2022 |
36Monitor | CVE-2023-39403No exploit | Parameter verification vulnerability in the installd module.huawei · emui · CWE-358 | Critical9.1 | — | 0.4% | Aug 13, 2023 |
36Monitor | CVE-2025-69234No exploit | Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.navercorp · whale · CWE-358 | Critical9.1 | — | 0.3% | Dec 30, 2025 |
35Monitor | CVE-2019-3894No exploit | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run thredhat · wildfly · CWE-358 | High8.8 | — | 1.5% | May 3, 2019 |
35Monitor | CVE-2016-10834No exploit | cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).cpanel · cpanel · CWE-358 | High8.8 | — | 1.4% | Aug 1, 2019 |
35Monitor | CVE-2024-6101No exploit | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory accessgoogle · chrome · CWE-358 | High8.8 | — | 0.8% | Jun 19, 2024 |
35Monitor | CVE-2021-26105No exploit | A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and belowfortinet · fortisandbox · CWE-358 | High8.8 | — | 0.5% | Mar 24, 2025 |
35Monitor | CVE-2026-1486No exploit | Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grantred hat · red hat build of keycloak 26.4 · CWE-358 | High8.8 | — | 0.5% | Feb 9, 2026 |
35Monitor | CVE-2025-3069No exploit | Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalationgoogle · chrome · CWE-358 | High8.8 | — | 0.4% | Apr 1, 2025 |
35Monitor | CVE-2025-66600No exploit | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.yokogawa electric corporation · fast/tools · CWE-358 | High8.8 | — | 0.3% | Feb 9, 2026 |
34Monitor | CVE-2017-15663Proof of concept | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.flexense · disk pulse · CWE-358 | High7.5 | — | 13.2% | Jan 10, 2018 |
34Monitor | CVE-2026-12577No exploit | DVP80ES3 Improperly Implemented Security Check for Standard vulnerabilitydeltaww · dvp80es3 · CWE-358 | High8.7 | — | 0.4% | Jul 1, 2026 |
33Monitor | CVE-2017-15662Proof of concept | In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.flexense · vx search · CWE-358 | High7.5 | — | 9.1% | Jan 10, 2018 |
33Monitor | CVE-2017-15664Proof of concept | In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.flexense · syncbreeze · CWE-358 | High7.5 | — | 9.1% | Jan 10, 2018 |
33Monitor | CVE-2017-15665Proof of concept | In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.flexense · diskboss · CWE-358 | High7.5 | — | 9.1% | Jan 10, 2018 |
32Monitor | CVE-2019-3806No exploit | An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received powerdns · recursor · CWE-358 | High8.1 | — | 1.5% | Jan 29, 2019 |
32Monitor | CVE-2016-10825No exploit | cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).cpanel · cpanel · CWE-358 | High8.1 | — | 1.1% | Aug 1, 2019 |
32Monitor | CVE-2023-2585No exploit | Keycloak: client access via device auth request spoofredhat · single sign-on · CWE-358 | High8.1 | — | 0.7% | Dec 21, 2023 |
32Monitor | CVE-2025-10457No exploit | Bluetooth: Out-Of-Context le_conn_rsp Handlingzephyrproject · zephyr · CWE-358 | High8.1 | — | 0.4% | Sep 19, 2025 |
- CVE-2016-1022943Plan
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checks
CriticalCVSS 9.8No exploitEPSS 13%linux · linux kernelApr 4, 2017
- CVE-2018-026842Plan
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, rem
CriticalCVSS 10.0No exploitEPSS 5%cisco · digital network architecture centerMay 16, 2018
- CVE-2019-674241Plan
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.
CriticalCVSS 9.8No exploitEPSS 6%samsung · galaxy s9 firmwareJun 3, 2019
- CVE-2023-326639Monitor
A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication check
CriticalCVSS 9.8No exploitEPSS 1%cyberpower · powerpanel serverAug 14, 2023
- CVE-2025-6258339Monitor
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CriticalCVSS 9.8No exploitEPSS 1%navercorp · whaleOct 16, 2025
- CVE-2026-4879737Monitor
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CriticalCVSS 9.3No exploitEPSS 1%mcp-tool-shop-org · backpropagateJun 17, 2026
- CVE-2022-2515236Monitor
ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvals
HighCVSS 8.8No exploitEPSS 2%itarian · on-premiseJun 9, 2022
- CVE-2023-3940336Monitor
Parameter verification vulnerability in the installd module.
CriticalCVSS 9.1No exploitEPSS 0%huawei · emuiAug 13, 2023
- CVE-2025-6923436Monitor
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
CriticalCVSS 9.1No exploitEPSS 0%navercorp · whaleDec 30, 2025
- CVE-2019-389435Monitor
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run th
HighCVSS 8.8No exploitEPSS 1%redhat · wildflyMay 3, 2019
- CVE-2016-1083435Monitor
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
HighCVSS 8.8No exploitEPSS 1%cpanel · cpanelAug 1, 2019
- CVE-2024-610135Monitor
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access
HighCVSS 8.8No exploitEPSS 1%google · chromeJun 19, 2024
- CVE-2021-2610535Monitor
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below
HighCVSS 8.8No exploitEPSS 1%fortinet · fortisandboxMar 24, 2025
- CVE-2026-148635Monitor
Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant
HighCVSS 8.8No exploitEPSS 0%red hat · red hat build of keycloak 26.4Feb 9, 2026
- CVE-2025-306935Monitor
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation
HighCVSS 8.8No exploitEPSS 0%google · chromeApr 1, 2025
- CVE-2025-6660035Monitor
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
HighCVSS 8.8No exploitEPSS 0%yokogawa electric corporation · fast/toolsFeb 9, 2026
- CVE-2017-1566334Monitor
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.
HighCVSS 7.5Proof of conceptEPSS 13%flexense · disk pulseJan 10, 2018
- CVE-2026-1257734Monitor
DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
HighCVSS 8.7No exploitEPSS 0%deltaww · dvp80es3Jul 1, 2026
- CVE-2017-1566233Monitor
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.
HighCVSS 7.5Proof of conceptEPSS 9%flexense · vx searchJan 10, 2018
- CVE-2017-1566433Monitor
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.
HighCVSS 7.5Proof of conceptEPSS 9%flexense · syncbreezeJan 10, 2018
- CVE-2017-1566533Monitor
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.
HighCVSS 7.5Proof of conceptEPSS 9%flexense · diskbossJan 10, 2018
- CVE-2019-380632Monitor
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received
HighCVSS 8.1No exploitEPSS 1%powerdns · recursorJan 29, 2019
- CVE-2016-1082532Monitor
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
HighCVSS 8.1No exploitEPSS 1%cpanel · cpanelAug 1, 2019
- CVE-2023-258532Monitor
Keycloak: client access via device auth request spoof
HighCVSS 8.1No exploitEPSS 1%redhat · single sign-onDec 21, 2023
- CVE-2025-1045732Monitor
Bluetooth: Out-Of-Context le_conn_rsp Handling
HighCVSS 8.1No exploitEPSS 0%zephyrproject · zephyrSep 19, 2025