VYPR

CWE-358

Improperly Implemented Security Check for Standard

BaseDraft

Description

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (136)

page 1 of 7
  • CVE-2024-7965HigKEVAug 21, 2024
    risk 0.71cvss 8.8epss 0.18

    Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2018-0268CriMay 17, 2018
    risk 0.65cvss 10.0epss 0.05

    A vulnerability in the container management subsystem of Cisco Digital Network Architecture (DNA) Center could allow an unauthenticated, remote attacker to bypass authentication and gain elevated privileges. This vulnerability is due to an insecure default configuration of the…

  • CVE-2025-66603CriFeb 9, 2026
    risk 0.64cvss 9.8epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OPTIONS method. An attacker could potentially use this information to carry out other attacks. The affected products and versions are as follows: FAST/TOOLS…

  • CVE-2025-62583CriOct 16, 2025
    risk 0.64cvss 9.8epss 0.00

    Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.

  • CVE-2023-4501CriSep 12, 2023
    risk 0.64cvss 9.8epss 0.01

    User authentication with username and password credentials is ineffective in OpenText (Micro Focus) Visual COBOL, COBOL Server, Enterprise Developer, and Enterprise Server (including product variants such as Enterprise Test Server), versions 7.0 patch updates 19 and 20, 8.0…

  • CVE-2023-3266CriAug 14, 2023
    risk 0.64cvss 9.8epss 0.01

    A non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checks if LDAP authentication is selected.An unauthenticated attacker can leverage this vulnerability to log in to the CypberPower PowerPanel…

  • CVE-2022-25152CriJun 9, 2022
    risk 0.64cvss 9.9epss 0.02

    The ITarian platform (SAAS / on-premise) offers the possibility to run code on agents via a function called procedures. It is possible to require a mandatory approval process. Due to a vulnerability in the approval process, present in any version prior to 6.35.37347.20040, a…

  • CVE-2019-6742CriJun 3, 2019
    risk 0.64cvss 9.8epss 0.06

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S9 prior to 1.4.20.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the GameServiceReceiver update…

  • CVE-2018-1270CriApr 6, 2018
    risk 0.63cvss 9.8epss 0.77

    Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker)…

  • CVE-2018-1275CriApr 11, 2018
    risk 0.61cvss 9.8epss 0.58

    Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker)…

  • CVE-2026-48797CriJun 17, 2026
    risk 0.60cvss epss 0.00

    Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI exposes a training control plane without authentication: dataset upload, model load, training start/stop, multi-run orchestration,…

  • CVE-2025-69234CriDec 30, 2025
    risk 0.59cvss 9.1epss 0.00

    Whale browser before 4.35.351.12 allows an attacker to escape the iframe sandbox in a sidebar environment.

  • CVE-2023-39403CriAug 13, 2023
    risk 0.59cvss 9.1epss 0.00

    Parameter verification vulnerability in the installd module. Successful exploitation of this vulnerability may cause sandbox files to be read and written without authorization.

  • CVE-2024-2174HigMar 6, 2024
    risk 0.58cvss 8.8epss 0.13

    Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2016-10229CriApr 4, 2017
    risk 0.58cvss 9.8epss 0.13

    udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a recv system call with the MSG_PEEK flag.

  • CVE-2026-50628CriJun 12, 2026
    risk 0.57cvss 9.8epss 0.01

    A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to…

  • CVE-2025-66600HigFeb 9, 2026
    risk 0.57cvss epss 0.00

    A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP Strict Transport Security) configuration. When an attacker performs a Man in the middle (MITM) attack, communications with the web server could be sniffed. …

  • CVE-2025-3069HigApr 2, 2025
    risk 0.57cvss 8.8epss 0.00

    Inappropriate implementation in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-6772HigJul 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2024-6101HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)