CWE-358: Improperly Implemented Security Check for Standard
The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
88 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-29103 — SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass
- CVE-2025-66600 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2025-59147 — Suricata is Vulnerable to Detection Bypass via Crafted Multiple SYN Packets
- CVE-2025-58308 — Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi
- CVE-2026-12577 — DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
- CVE-2025-32086 — Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors whe
- CVE-2026-40597 — MantisBT has a Content Security Policy bypass via attachments
- CVE-2025-66607 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains
- CVE-2025-66601 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify
- CVE-2024-23592 — An authentication bypass vulnerability was reported in Lenovo devices with Synaptics fingerprint readers that could allo
- CVE-2026-44473 — Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
- CVE-2026-2645 — Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
- CVE-2025-66323 — Vulnerability of improper criterion security check in the card module. Impact: Successful exploitation of this vulnerabi
- CVE-2025-62002 — BullWall Ransomware Containment file count detection bypass
- CVE-2026-44475 — Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-65058 — Trezor Safe improper security check in on-device display
- CVE-2026-22618 — A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was
- CVE-2025-25255 — An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 th
Recently published
- CVE-2026-46582 — A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
- CVE-2026-65058 — Trezor Safe improper security check in on-device display
- CVE-2026-54431 — Improper Data Validation in liboauth2
- CVE-2026-12577 — DVP80ES3 Improperly Implemented Security Check for Standard vulnerability
- CVE-2026-48797 — Backpropagate: backprop ui --auth and backprop ui --share do not enforce authentication
- CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover
- CVE-2026-44473 — Ella Core: UE Downlink Redirection via Forged PDUSessionResourceSetupResponse
- CVE-2026-44475 — Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
- CVE-2026-44474 — Ella Core: Handover failures during concurrent Security Mode Command
- CVE-2026-40597 — MantisBT has a Content Security Policy bypass via attachments
- CVE-2025-31983 — HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header
- CVE-2025-31970 — HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability
- CVE-2026-22618 — A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was
- CVE-2026-35679 — Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could
- CVE-2026-29103 — SuiteCRM Vulnerable to Remote Code Execution via Module Loader Package Scanner Bypass
- CVE-2026-2645 — Acceptance of CertificateVerify Message before ClientKeyExchange in TLS 1.2
- CVE-2026-25315 — WordPress hCaptcha for WP plugin <= 4.21.1 - Broken Access Control vulnerability
- CVE-2025-13333 — IBM WebSphere Application Server could provide weaker than expected security
- CVE-2025-66600 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP