The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.
Volume of CVEs assigned to CWE-573 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41583CRITICAL ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad version 4.3.1 and prior to zebra-script version 5.0.2, after a refactoring, Zebra failed to validate a consensus rul | May 8, 2026 | 9.1 | 36 | NO | NO |
CVE-2026-59998MEDIUM sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory. | Jul 8, 2026 | 6.5 | 32 | NO | NO |
CVE-2026-28498HIGH Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.9, a library-level vulnerability was identified in the Authlib Python library concer | Mar 16, 2026 | 7.5 | 28 | NO | NO |
CVE-2025-69202MEDIUM Axios Cache Interceptor is a cache interceptor for axios. Prior to version 1.11.1, when a server calls an upstream service using different auth tokens, axios-cache-interceptor retu | Dec 29, 2025 | 6.5 | 22 | NO | NO |
CVE-2025-21601HIGH An Improper Following of Specification by Caller vulnerability in web management (J-Web, Captive Portal, 802.1X, Juniper Secure Connect (JSC) of Juniper Networks Junos OS on SRX Se | Apr 9, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-69287MEDIUM The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version 2.0.0, a cryptographic vulnerability in the TypeScript SDK's | Feb 18, 2026 | 5.4 | 19 | NO | NO |
CVE-2019-14829MEDIUM A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly resp | Mar 19, 2021 | 4.3 | 17 | NO | NO |
libsnowflakeclient is the Snowflake Connector for C/C++. Versions starting from 0.5.0 to before 2.2.0, incorrectly treat malformed requests that caused the HTTP response status cod | Apr 29, 2025 | 3.3 | 14 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.