A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OP
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Rem
A flaw was found in Keycloak. A vulnerability exists in the jwt-authorization-grant flow where the server fails to verif
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip
Improperly implemented security check for standard in Windows Secure Boot allows an authorized attacker to bypass a secu
In wolfSSL 5.8.2 and earlier, a logic flaw existed in the TLS 1.2 server state machine implementation. The server could
Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, a radio with a valid NG Setup can send a forged P
Inappropriate implementation in WebAPKs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not specify
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core does not verify the UE Security Capabil
Inappropriate implementation in Keyboard in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arb
A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The response header contains
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Polic
Trezor Safe 3, Safe 5, and Safe 7 firmware contains a confirmation-binding flaw in the Ethereum sign_tx / sign_tx_eip155
IBM WebSphere Application Server 9.0, and 8.5 could provide weaker than expected security during system administration o
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigati
HCL BigFix Service Management (SM) is affected by a security misconfiguration vulnerability due to CSP header. This cou
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the
Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concur
In NLnet Labs Unbound 1.6.0 up to and including 1.25.1, a replay of a wildcard rrset as another piece of data, could be
Zcash zcashd before 6.12.0 allows invalid transactions to be accepted under certain conditions, which potentially could
A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product lacks HSTS (HTTP
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, given any pre-existing XSS
Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th
DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.
In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header conta
Frequently Asked Questions
What is CWE-358?
CWE-358 (CWE-358) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-358?
There are 33 CVE records associated with CWE-358 in our database. Of these, 3 are critical severity, 7 are high severity, and 12 are medium severity.
How can I protect against CWE-358 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-358 using AI-powered security agents.
Detect CWE-358 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-358 vulnerabilities across your infrastructure.
Get Started