CWE-358

Improperly Implemented Security Check for Standard

Parent: CWE-573 - Improper Following of Specification by Caller

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

132 vulnerabilities with CWE-358
CVE-2024-33510 MEDIUM
FortiOS <7.4.3, <7.2.8, <7.0.16 - Injection
CVSS 4.3
CVE-2024-40650 HIGH
Android - Missing Authorization Leading to Factory Reset Protection Bypass
CVSS 7.8
CVE-2024-36511 LOW
FortiADC WAF <7.4.4 - Info Disclosure
CVSS 3.7
CVE-2024-7965 HIGH KEV
Google Chrome < 128.0.6613.84 - Remote Code Execution via V8 Heap Corruption
CVSS 8.8
CVE-2024-41907 MEDIUM
SINEC Traffic Analyzer <V2.0 - Info Disclosure
CVSS 4.2
CVE-2024-7003 MEDIUM
Google Chrome < 127.0.6533.72 - UI Spoofing via FedCM Inappropriate Implementation
CVSS 4.3
CVE-2024-6995 MEDIUM
Chrome < 127.0.6533.72 - URL Spoofing via Fullscreen UI Gestures
CVSS 4.7
CVE-2024-5500 MEDIUM
Google Chrome <1.3.36.351 - Auth Bypass
CVSS 6.5
CVE-2024-6772 HIGH
Google Chrome <126.0.6478.182 - Memory Corruption
CVSS 8.8
CVE-2024-6101 HIGH
Google Chrome < 126.0.6478.114 - Out of Bounds Memory Access in V8
CVSS 8.8
CVE-2024-27842 HIGH
macOS Sonoma <14.5 - Privilege Escalation
CVSS 7.8
CVE-2024-2617 HIGH
Hitachi Energy RTU500 CMU Firmware 13.2.1-13.2.6, 13.4.1-13.4.3, 13.5.1-13.5.2 - Authenticated Firmware Update Bypass
CVSS 7.2
CVE-2024-3845 MEDIUM
Google Chrome <124.0.6367.60 - CSRF
CVSS 4.3
CVE-2024-3844 MEDIUM
Google Chrome < 124.0.6367.60 - UI Spoofing via Crafted Chrome Extension
CVSS 4.3
CVE-2024-3838 MEDIUM
Google Chrome < 124.0.6367.60 - UI Spoofing via Autofill
CVSS 5.5
CVE-2024-25545 HIGH
Weave Desktop 7.78.10-7.84.1 - Local Code Execution via nwjs Framework Script Injection
CVSS 7.8
CVE-2024-23592 MEDIUM
Lenovo Synaptics Fingerprint Readers - Authentication Bypass via Fingerprint Replay
CVSS 6.3
CVE-2024-2174 HIGH
Google Chrome <122.0.6261.111 - Heap Corruption
CVSS 8.8
CVE-2023-2585 LOW
Keycloak - Auth Bypass
CVSS 3.5
CVE-2023-40445 HIGH
iPadOS 17.0 - Improperly Implemented Security Check for Standard
CVSS 7.5
CVE-2023-4501 CRITICAL
OpenText (Micro Focus) Visual COBOL <9.0 - Auth Bypass
CVSS 9.8
CVE-2023-3266 CRITICAL
CypberPower PowerPanel Enterprise - Auth Bypass
CVSS 9.8
CVE-2023-39403 CRITICAL
Huawei EMUI and HarmonyOS - Improper Authorization in installd Module
CVSS 9.1
CVE-2023-28601 HIGH
Zoom for Windows <5.14.0 - Memory Corruption
CVSS 8.3
CVE-2023-28113 MEDIUM
russh <0.36.2-0.37.1 - Info Disclosure
CVSS 5.9
Details
Vulnerabilities 132