The product does not implement or incorrectly implements one or more security-relevant checks as specified by the design of a standardized algorithm, protocol, or technique.
Volume of CVEs assigned to CWE-358 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
132 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-7965HIGH Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium secur | Aug 21, 2024 | 8.8 | 77 | YES | NO |
CVE-2018-1270CRITICAL Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a si | Apr 6, 2018 | 9.8 | 72 | NO | NO |
CVE-2018-1275CRITICAL Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a si | Apr 11, 2018 | 9.8 | 64 | NO | NO |
CVE-2026-50628CRITICAL A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
sec | Jun 12, 2026 | 9.8 | 40 | NO | NO |
CVE-2016-10229CRITICAL udp.c in the Linux kernel before 4.5 allows remote attackers to execute arbitrary code via UDP traffic that triggers an unsafe second checksum calculation during execution of a rec | Apr 4, 2017 | 9.8 | 40 | NO | NO |
CVE-2017-15663HIGH In Flexense Disk Pulse Enterprise v10.1.18, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to contr | Jan 10, 2018 | 7.5 | 38 | NO | YES |
CVE-2026-12577HIGH DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability. | Jul 1, 2026 | 8.7 | 37 | NO | NO |
CVE-2017-15665HIGH In Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to control p | Jan 10, 2018 | 7.5 | 37 | NO | YES |
CVE-2017-15662HIGH In Flexense VX Search Enterprise v10.1.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GET_INFO packet sent to contro | Jan 10, 2018 | 7.5 | 37 | NO | YES |
CVE-2026-44513HIGH Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution | May 14, 2026 | 8.8 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.