CWE-358
Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
132 vulnerabilities with CWE-358
CVE-2026-46582
LOW
A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVSS 3.7
CVE-2026-65058
MEDIUM
Trezor Safe improper security check in on-device display
CVSS 5.3
CVE-2026-49783
HIGH
Microsoft Windows 10 Version 1607 - Secure Boot Security Feature Bypass Vulnerability
CVSS 7.8
CVE-2026-54431
MEDIUM
Improper Data Validation in liboauth2
CVE-2026-12577
HIGH
DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
CVE-2026-57915
HIGH
Apache Kerby: Kerberos Pre-Authentication Bypass
CVSS 7.3
CVE-2026-48797
CRITICAL
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-50628
CRITICAL
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
CVSS 9.8
CVE-2026-11127
MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via WebAPK
CVSS 6.5
CVE-2026-11122
MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-44475
MEDIUM
Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
CVSS 6.1
CVE-2026-44474
LOW
Ella Core: Handover failures during concurrent Security Mode Command
CVSS 3.7
CVE-2026-44473
HIGH
Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVSS 7.1
CVE-2026-42082
LOW
free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
CVSS 3.7
CVE-2026-42081
MEDIUM
free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
CVSS 6.1
CVE-2026-40597
HIGH
MantisBT <2.28.2 Attachments - Content Security Policy Bypass
CVE-2026-44513
HIGH
Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVSS 8.8
CVE-2026-45109
HIGH
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVSS 7.5
CVE-2026-28914
MEDIUM
Apple macOS <26.5 - Gatekeeper Bypass
CVSS 5.5
CVE-2026-22618
MEDIUM
Eaton IPP software <2.0 - Security Misconfiguration
CVSS 5.9
CVE-2026-5894
MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 4.3
CVE-2026-35679
LOW
Zcash zcashd <6.12.0 - Invalid Transaction Validation
CVSS 3.5
CVE-2026-29103
CRITICAL
SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass
CVSS 9.1
CVE-2026-2645
HIGH
Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
CVSS 7.5
CVE-2026-1486
HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Token Issuance via Disabled Identity Provider Bypass
CVSS 8.8
Details
Vulnerabilities
132