VYPR

CWE-358

Improperly Implemented Security Check for Standard

BaseDraft

Description

The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.

Hierarchy (View 1000)

Children

none

CVEs mapped to this weakness (136)

page 7 of 7
  • CVE-2017-2604MedMay 15, 2018
    risk 0.21cvss 4.3epss 0.01

    In Jenkins before versions 2.44, 2.32.2 low privilege users were able to act on administrative monitors due to them not being consistently protected by permission checks (SECURITY-371).

  • CVE-2017-2611MedMay 8, 2018
    risk 0.21cvss 4.3epss 0.02

    Jenkins before versions 2.44, 2.32.2 is vulnerable to an insufficient permission check for periodic processes (SECURITY-389). The URLs /workspaceCleanup and /fingerprintCleanup did not perform permission checks, allowing users with read access to Jenkins to trigger these…

  • CVE-2025-8204LowJul 26, 2025
    risk 0.20cvss 3.1epss 0.01

    A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS Handler. The manipulation leads to security check for standard. The attack can be launched remotely. The…

  • CVE-2026-46582LowJul 22, 2026
    risk 0.17cvss 3.7epss 0.00

    In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be briefly considered DNSSEC secure based only on the RRSIG validation and stored into cache, before later validation treats it as bogus based on NSEC validation.…

  • CVE-2026-44474LowMay 27, 2026
    risk 0.17cvss 3.7epss 0.00

    Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concurrent running of security procedures defined in TS 33.501 §6.9.5.1 — it could send a NAS Security Mode Command while an N2 handover was still pending (and…

  • CVE-2026-42082LowMay 27, 2026
    risk 0.17cvss 3.7epss 0.00

    free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AMF does not check for ongoing N2 handover procedures before initiating a NAS…

  • CVE-2025-49011LowJun 6, 2025
    risk 0.17cvss 3.7epss 0.00

    SpiceDB is an open source database for storing and querying fine-grained authorization data. Prior to version 1.44.2, on schemas involving arrows with caveats on the arrow’ed relation, when the path to resolve a CheckPermission request involves the evaluation of multiple…

  • CVE-2026-35679LowApr 5, 2026
    risk 0.16cvss 3.5epss 0.00

    Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could have resulted in the draining of user funds from the Sprout pool. It was sometimes not verifying Sprout proofs.

  • CVE-2023-2585LowDec 21, 2023
    risk 0.16cvss 3.5epss 0.01

    Keycloak's device authorization grant does not correctly validate the device code and client ID. An attacker client could abuse the missing validation to spoof a client consent request and trick an authorization admin into granting consent to a malicious OAuth client or possible…

  • CVE-2020-8352LowNov 11, 2020
    risk 0.16cvss 2.4epss 0.00

    In some Lenovo Desktop models, the Configuration Change Detection BIOS setting failed to detect SATA configuration changes.

  • CVE-2024-12056LowDec 4, 2024
    risk 0.15cvss epss 0.00

    The Client secret is not checked when using the OAuth Password grant type. By exploiting this vulnerability, an attacker could connect to a web server using a client application not explicitly authorized as part of the OAuth deployment. Exploitation requires valid credentials…

  • CVE-2026-65058MedJul 21, 2026
    risk 0.00cvss 5.3epss 0.00

    Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip1559 flow. For contract interactions, the device confirms only the initial calldata chunk while the signature commits to the full streamed calldata. An attacker…

  • CVE-2026-49783HigJul 14, 2026
    risk 0.00cvss 7.8epss 0.00

    Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.

  • CVE-2026-12577HigJul 1, 2026
    risk 0.00cvss epss 0.00

    DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.

  • CVE-2025-59147HigOct 1, 2025
    risk 0.00cvss 7.5epss 0.00

    Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suricata community. Versions 7.0.11 and below, as well as 8.0.0, are vulnerable to detection bypass when crafted traffic sends multiple SYN packets with different…

  • CVE-2018-17175MedSep 18, 2018
    risk 0.00cvss 5.3epss 0.02

    In the marshmallow library before 2.15.1 and 3.x before 3.0.0b9 for Python, the schema "only" option treats an empty list as implying no "only" option, which allows a request that was intended to expose no fields to instead expose all fields (if the schema is being filtered…