CWE-358
Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
132 vulnerabilities with CWE-358
CVE-2025-31983
LOW
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
CVSS 3.7
CVE-2025-31970
MEDIUM
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
CVSS 5.3
CVE-2025-13333
MEDIUM
IBM WebSphere 9.0/8.5 - Auth Bypass
CVSS 4.4
CVE-2025-66607
MEDIUM
Yokogawa FAST/TOOLS R9.01-R10.04 - Open Redirect via Insecure Response Header
CVSS 5.3
CVE-2025-66603
CRITICAL
FAST/TOOLS <10.04 - Info Disclosure
CVSS 9.8
CVE-2025-66601
MEDIUM
Yokogawa Electric Corporation FAST/TOOLS <10.04 - XSS
CVSS 6.1
CVE-2025-66600
HIGH
FAST/TOOLS <10.04 - Info Disclosure
CVE-2025-69234
CRITICAL
Whale < 4.35.351.12 - Sandbox Escape via Sidebar Iframe
CVSS 9.1
CVE-2025-62002
MEDIUM
BullWall Ransomware Containment <4.6.1.4 - Authenticated RCE
CVSS 4.3
CVE-2025-66323
MEDIUM
HarmonyOS - Denial of Service via Card Module Security Check Bypass
CVSS 5.3
CVE-2025-58308
HIGH
HarmonyOS - Improperly Implemented Security Check in Call Module
CVSS 7.3
CVE-2025-62585
HIGH
Whale < 4.33.325.17 - Content Security Policy Bypass via Dual-Tab Scheme
CVSS 7.5
CVE-2025-62583
CRITICAL
Whale Browser < 4.33.325.17 - Iframe Sandbox Escape in Dual-Tab Environment
CVSS 9.8
CVE-2025-25255
MEDIUM
Fortinet FortiOS <7.6.3 - Auth Bypass
CVSS 5.3
CVE-2025-31969
MEDIUM
HCL Unica < 25.1.0 - Content Security Policy Misconfiguration
CVSS 4.0
CVE-2025-59147
HIGH
Suricata <7.0.11 & 8.0.0 - Detection Bypass
CVSS 7.5
CVE-2025-10457
MEDIUM
Zephyr < 4.1.0 - Improperly Implemented Security Check for BLE Connection Response
CVSS 4.3
CVE-2025-43262
MEDIUM
macOS < 26.0 - Unprotected USB Access via Restricted Mode Bypass
CVSS 5.1
CVE-2025-32086
HIGH
Intel Xeon 6 - Privilege Escalation
CVSS 7.2
CVE-2025-8204
LOW
Comodo Dragon <134.0.6998.179 - Info Disclosure
CVSS 3.1
CVE-2025-49011
LOW
SpiceDB < 1.44.2 - Improperly Implemented Security Check for Standard
CVSS 3.7
CVE-2025-3069
HIGH
Google Chrome < 135.0.7049.52 - Privilege Escalation via Extensions
CVSS 8.8
CVE-2025-21267
MEDIUM
Microsoft Edge Chromium < 133.0.3065.51 - Spoofing via Improperly Implemented Security Check
CVSS 4.4
CVE-2024-55599
MEDIUM
FortiOS 6.4-7.6.0, 7.4<=7.4.7 and FortiProxy 7.0-7.6.1, 7.4<=7.4.8 - Unauthenticated DNS Filter Bypass via Apple Devices
CVSS 5.3
CVE-2024-12056
LOW
OAuth Client - Privilege Escalation
Details
Vulnerabilities
132