İçeriğe atla
Noroxi

CWE-358 · 113 kayıt

Improperly Implemented Security Check for Standard

Bu sınıftaki CVE’ler

113 kayıt

  • CVE-2016-10229
    43Planlayın

    udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checks

    KritikCVSS 9,8İstismar yokEPSS %13

    linux · linux kernel4 Nis 2017

  • CVE-2018-0268
    42Planlayın

    A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, rem

    KritikCVSS 10,0İstismar yokEPSS %5

    cisco · digital network architecture center16 May 2018

  • CVE-2019-6742
    41Planlayın

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.

    KritikCVSS 9,8İstismar yokEPSS %6

    samsung · galaxy s9 firmware3 Haz 2019

  • CVE-2023-3266
    39İzleyin

    A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication check

    KritikCVSS 9,8İstismar yokEPSS %1

    cyberpower · powerpanel server14 Ağu 2023

  • CVE-2025-62583
    39İzleyin

    Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

    KritikCVSS 9,8İstismar yokEPSS %1

    navercorp · whale16 Eki 2025

  • CVE-2026-48797
    37İzleyin

    Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication

    KritikCVSS 9,3İstismar yokEPSS %1

    mcp-tool-shop-org · backpropagate17 Haz 2026

  • CVE-2022-25152
    36İzleyin

    ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvals

    YüksekCVSS 8,8İstismar yokEPSS %2

    itarian · on-premise9 Haz 2022

  • CVE-2023-39403
    36İzleyin

    Parameter verification vulnerability in the installd module.

    KritikCVSS 9,1İstismar yokEPSS %0

    huawei · emui13 Ağu 2023

  • CVE-2025-69234
    36İzleyin

    Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

    KritikCVSS 9,1İstismar yokEPSS %0

    navercorp · whale29 Ara 2025

  • CVE-2019-3894
    35İzleyin

    It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run th

    YüksekCVSS 8,8İstismar yokEPSS %1

    redhat · wildfly3 May 2019

  • CVE-2016-10834
    35İzleyin

    cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).

    YüksekCVSS 8,8İstismar yokEPSS %1

    cpanel · cpanel1 Ağu 2019

  • CVE-2024-6101
    35İzleyin

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access

    YüksekCVSS 8,8İstismar yokEPSS %1

    google · chrome19 Haz 2024

  • CVE-2021-26105
    35İzleyin

    A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below

    YüksekCVSS 8,8İstismar yokEPSS %1

    fortinet · fortisandbox24 Mar 2025

  • CVE-2026-1486
    35İzleyin

    Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant

    YüksekCVSS 8,8İstismar yokEPSS %0

    red hat · red hat build of keycloak 26.49 Şub 2026

  • CVE-2025-3069
    35İzleyin

    Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation

    YüksekCVSS 8,8İstismar yokEPSS %0

    google · chrome1 Nis 2025

  • CVE-2025-66600
    35İzleyin

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.

    YüksekCVSS 8,8İstismar yokEPSS %0

    yokogawa electric corporation · fast/tools9 Şub 2026

  • CVE-2017-15663
    34İzleyin

    In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.

    YüksekCVSS 7,5Kavram kanıtıEPSS %13

    flexense · disk pulse10 Oca 2018

  • CVE-2026-12577
    34İzleyin

    DVP80ES3 Improperly Implemented Security Check for Standard vulnerability

    YüksekCVSS 8,7İstismar yokEPSS %0

    deltaww · dvp80es31 Tem 2026

  • CVE-2017-15664
    33İzleyin

    In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.

    YüksekCVSS 7,5Kavram kanıtıEPSS %9

    flexense · syncbreeze10 Oca 2018

  • CVE-2017-15665
    33İzleyin

    In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.

    YüksekCVSS 7,5Kavram kanıtıEPSS %9

    flexense · diskboss10 Oca 2018

  • CVE-2017-15662
    33İzleyin

    In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.

    YüksekCVSS 7,5Kavram kanıtıEPSS %9

    flexense · vx search10 Oca 2018

  • CVE-2019-3806
    32İzleyin

    An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received

    YüksekCVSS 8,1İstismar yokEPSS %1

    powerdns · recursor29 Oca 2019

  • CVE-2016-10825
    32İzleyin

    cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

    YüksekCVSS 8,1İstismar yokEPSS %1

    cpanel · cpanel1 Ağu 2019

  • CVE-2023-2585
    32İzleyin

    Keycloak: client access via device auth request spoof

    YüksekCVSS 8,1İstismar yokEPSS %1

    redhat · single sign-on21 Ara 2023

  • CVE-2025-10457
    32İzleyin

    Bluetooth: Out-Of-Context le_conn_rsp Handling

    YüksekCVSS 8,1İstismar yokEPSS %0

    zephyrproject · zephyr19 Eyl 2025

Tüm zafiyet sınıfları