CWE-358 · 113 kayıt
Improperly Implemented Security Check for Standard
Bu sınıftaki CVE’ler
113 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2016-10229İstismar yok | udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checkslinux · linux kernel · CWE-358 | Kritik9,8 | — | %12,8 | 4 Nis 2017 |
42Planlayın | CVE-2018-0268İstismar yok | A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remcisco · digital network architecture center · CWE-358 | Kritik10,0 | — | %5,0 | 16 May 2018 |
41Planlayın | CVE-2019-6742İstismar yok | This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.samsung · galaxy s9 firmware · CWE-358 | Kritik9,8 | — | %5,9 | 3 Haz 2019 |
39İzleyin | CVE-2023-3266İstismar yok | A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checkcyberpower · powerpanel server · CWE-358 | Kritik9,8 | — | %0,9 | 14 Ağu 2023 |
39İzleyin | CVE-2025-62583İstismar yok | Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.navercorp · whale · CWE-358 | Kritik9,8 | — | %0,5 | 16 Eki 2025 |
37İzleyin | CVE-2026-48797İstismar yok | Backpropagate: backprop ui --auth and backprop ui --share do not enforce authenticationmcp-tool-shop-org · backpropagate · CWE-358 | Kritik9,3 | — | %0,6 | 17 Haz 2026 |
36İzleyin | CVE-2022-25152İstismar yok | ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvalsitarian · on-premise · CWE-358 | Yüksek8,8 | — | %1,8 | 9 Haz 2022 |
36İzleyin | CVE-2023-39403İstismar yok | Parameter verification vulnerability in the installd module.huawei · emui · CWE-358 | Kritik9,1 | — | %0,4 | 13 Ağu 2023 |
36İzleyin | CVE-2025-69234İstismar yok | Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.navercorp · whale · CWE-358 | Kritik9,1 | — | %0,3 | 29 Ara 2025 |
35İzleyin | CVE-2019-3894İstismar yok | It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run thredhat · wildfly · CWE-358 | Yüksek8,8 | — | %1,5 | 3 May 2019 |
35İzleyin | CVE-2016-10834İstismar yok | cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).cpanel · cpanel · CWE-358 | Yüksek8,8 | — | %1,4 | 1 Ağu 2019 |
35İzleyin | CVE-2024-6101İstismar yok | Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory accessgoogle · chrome · CWE-358 | Yüksek8,8 | — | %0,8 | 19 Haz 2024 |
35İzleyin | CVE-2021-26105İstismar yok | A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and belowfortinet · fortisandbox · CWE-358 | Yüksek8,8 | — | %0,5 | 24 Mar 2025 |
35İzleyin | CVE-2026-1486İstismar yok | Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grantred hat · red hat build of keycloak 26.4 · CWE-358 | Yüksek8,8 | — | %0,5 | 9 Şub 2026 |
35İzleyin | CVE-2025-3069İstismar yok | Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalationgoogle · chrome · CWE-358 | Yüksek8,8 | — | %0,4 | 1 Nis 2025 |
35İzleyin | CVE-2025-66600İstismar yok | A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.yokogawa electric corporation · fast/tools · CWE-358 | Yüksek8,8 | — | %0,3 | 9 Şub 2026 |
34İzleyin | CVE-2017-15663Kavram kanıtı | In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.flexense · disk pulse · CWE-358 | Yüksek7,5 | — | %13,2 | 10 Oca 2018 |
34İzleyin | CVE-2026-12577İstismar yok | DVP80ES3 Improperly Implemented Security Check for Standard vulnerabilitydeltaww · dvp80es3 · CWE-358 | Yüksek8,7 | — | %0,4 | 1 Tem 2026 |
33İzleyin | CVE-2017-15664Kavram kanıtı | In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.flexense · syncbreeze · CWE-358 | Yüksek7,5 | — | %9,1 | 10 Oca 2018 |
33İzleyin | CVE-2017-15665Kavram kanıtı | In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.flexense · diskboss · CWE-358 | Yüksek7,5 | — | %9,1 | 10 Oca 2018 |
33İzleyin | CVE-2017-15662Kavram kanıtı | In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.flexense · vx search · CWE-358 | Yüksek7,5 | — | %9,1 | 10 Oca 2018 |
32İzleyin | CVE-2019-3806İstismar yok | An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received powerdns · recursor · CWE-358 | Yüksek8,1 | — | %1,5 | 29 Oca 2019 |
32İzleyin | CVE-2016-10825İstismar yok | cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).cpanel · cpanel · CWE-358 | Yüksek8,1 | — | %1,1 | 1 Ağu 2019 |
32İzleyin | CVE-2023-2585İstismar yok | Keycloak: client access via device auth request spoofredhat · single sign-on · CWE-358 | Yüksek8,1 | — | %0,7 | 21 Ara 2023 |
32İzleyin | CVE-2025-10457İstismar yok | Bluetooth: Out-Of-Context le_conn_rsp Handlingzephyrproject · zephyr · CWE-358 | Yüksek8,1 | — | %0,4 | 19 Eyl 2025 |
- CVE-2016-1022943Planlayın
udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checks
KritikCVSS 9,8İstismar yokEPSS %13linux · linux kernel4 Nis 2017
- CVE-2018-026842Planlayın
A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, rem
KritikCVSS 10,0İstismar yokEPSS %5cisco · digital network architecture center16 May 2018
- CVE-2019-674241Planlayın
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2.
KritikCVSS 9,8İstismar yokEPSS %6samsung · galaxy s9 firmware3 Haz 2019
- CVE-2023-326639İzleyin
A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication check
KritikCVSS 9,8İstismar yokEPSS %1cyberpower · powerpanel server14 Ağu 2023
- CVE-2025-6258339İzleyin
Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
KritikCVSS 9,8İstismar yokEPSS %1navercorp · whale16 Eki 2025
- CVE-2026-4879737İzleyin
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
KritikCVSS 9,3İstismar yokEPSS %1mcp-tool-shop-org · backpropagate17 Haz 2026
- CVE-2022-2515236İzleyin
ITarian - Any user with a valid session token can create and execute agent procedures and bypass mandatory approvals
YüksekCVSS 8,8İstismar yokEPSS %2itarian · on-premise9 Haz 2022
- CVE-2023-3940336İzleyin
Parameter verification vulnerability in the installd module.
KritikCVSS 9,1İstismar yokEPSS %0huawei · emui13 Ağu 2023
- CVE-2025-6923436İzleyin
Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.
KritikCVSS 9,1İstismar yokEPSS %0navercorp · whale29 Ara 2025
- CVE-2019-389435İzleyin
It was discovered that the ElytronManagedThread in Wildfly's Elytron subsystem in versions from 11 to 16 stores a SecurityIdentity to run th
YüksekCVSS 8,8İstismar yokEPSS %1redhat · wildfly3 May 2019
- CVE-2016-1083435İzleyin
cPanel before 55.9999.141 allows account-suspension bypass via ftp (SEC-105).
YüksekCVSS 8,8İstismar yokEPSS %1cpanel · cpanel1 Ağu 2019
- CVE-2024-610135İzleyin
Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access
YüksekCVSS 8,8İstismar yokEPSS %1google · chrome19 Haz 2024
- CVE-2021-2610535İzleyin
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below
YüksekCVSS 8,8İstismar yokEPSS %1fortinet · fortisandbox24 Mar 2025
- CVE-2026-148635İzleyin
Org.keycloak.protocol.oidc.grants: disabled identity providers are still accepted for jwt authorization grant
YüksekCVSS 8,8İstismar yokEPSS %0red hat · red hat build of keycloak 26.49 Şub 2026
- CVE-2025-306935İzleyin
Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation
YüksekCVSS 8,8İstismar yokEPSS %0google · chrome1 Nis 2025
- CVE-2025-6660035İzleyin
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
YüksekCVSS 8,8İstismar yokEPSS %0yokogawa electric corporation · fast/tools9 Şub 2026
- CVE-2017-1566334İzleyin
In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %13flexense · disk pulse10 Oca 2018
- CVE-2026-1257734İzleyin
DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0deltaww · dvp80es31 Tem 2026
- CVE-2017-1566433İzleyin
In Flexense Sync Breeze Enterprise v10.1.16, the Control Protocol suffers from a denial of service vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %9flexense · syncbreeze10 Oca 2018
- CVE-2017-1566533İzleyin
In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %9flexense · diskboss10 Oca 2018
- CVE-2017-1566233İzleyin
In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability.
YüksekCVSS 7,5Kavram kanıtıEPSS %9flexense · vx search10 Oca 2018
- CVE-2019-380632İzleyin
An issue has been found in PowerDNS Recursor versions after 4.1.3 before 4.1.9 where Lua hooks are not properly applied to queries received
YüksekCVSS 8,1İstismar yokEPSS %1powerdns · recursor29 Oca 2019
- CVE-2016-1082532İzleyin
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
YüksekCVSS 8,1İstismar yokEPSS %1cpanel · cpanel1 Ağu 2019
- CVE-2023-258532İzleyin
Keycloak: client access via device auth request spoof
YüksekCVSS 8,1İstismar yokEPSS %1redhat · single sign-on21 Ara 2023
- CVE-2025-1045732İzleyin
Bluetooth: Out-Of-Context le_conn_rsp Handling
YüksekCVSS 8,1İstismar yokEPSS %0zephyrproject · zephyr19 Eyl 2025