CWE-358

Improperly Implemented Security Check for Standard

Parent: CWE-573 - Improper Following of Specification by Caller

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

132 vulnerabilities with CWE-358
CVE-2026-46582 LOW
A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVSS 3.7
CVE-2026-65058 MEDIUM
Trezor Safe improper security check in on-device display
CVSS 5.3
CVE-2026-49783 HIGH
Microsoft Windows 10 Version 1607 - Secure Boot Security Feature Bypass Vulnerability
CVSS 7.8
CVE-2026-54431 MEDIUM
Improper Data Validation in liboauth2
CVE-2026-12577 HIGH
DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
CVE-2026-57915 HIGH
Apache Kerby: Kerberos Pre-Authentication Bypass
CVSS 7.3
CVE-2026-48797 CRITICAL
Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
CVE-2026-50628 CRITICAL
Apache CXF: OAuth2: Inverted IP Binding Check Defeats Security Control
CVSS 9.8
CVE-2026-11127 MEDIUM
Google Chrome < 149.0.7827.53 - Domain Spoofing via WebAPK
CVSS 6.5
CVE-2026-11122 MEDIUM
Google Chrome - XSS
CVSS 6.1
CVE-2026-44475 MEDIUM
Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
CVSS 6.1
CVE-2026-44474 LOW
Ella Core: Handover failures during concurrent Security Mode Command
CVSS 3.7
CVE-2026-44473 HIGH
Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
CVSS 7.1
CVE-2026-42082 LOW
free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
CVSS 3.7
CVE-2026-42081 MEDIUM
free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
CVSS 6.1
CVE-2026-40597 HIGH
MantisBT <2.28.2 Attachments - Content Security Policy Bypass
CVE-2026-44513 HIGH
Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components
CVSS 8.8
CVE-2026-45109 HIGH
Next.js: Middleware / Proxy bypass in App Router applications via segment-prefetch routes
CVSS 7.5
CVE-2026-28914 MEDIUM
Apple macOS <26.5 - Gatekeeper Bypass
CVSS 5.5
CVE-2026-22618 MEDIUM
Eaton IPP software <2.0 - Security Misconfiguration
CVSS 5.9
CVE-2026-5894 MEDIUM
Google Chrome <147.0.7727.55 - Auth Bypass
CVSS 4.3
CVE-2026-35679 LOW
Zcash zcashd <6.12.0 - Invalid Transaction Validation
CVSS 3.5
CVE-2026-29103 CRITICAL
SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass
CVSS 9.1
CVE-2026-2645 HIGH
Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
CVSS 7.5
CVE-2026-1486 HIGH
Keycloak 26.5.0-26.5.2 - Unauthenticated Token Issuance via Disabled Identity Provider Bypass
CVSS 8.8
Details
Vulnerabilities 132