Snuffleupagus is a module that raises the cost of attacks against website by killing bug classes and providing a virtual
Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerabili
OpenViking prior to version 0.3.9 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route su
Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit
An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur
Incorrect authorization in .NET allows an unauthorized attacker to bypass a security feature over a network.
Not failing securely ('failing open') in Visual Studio Code allows an unauthorized attacker to bypass a security feature
Helm is a package manager for Charts for Kubernetes. From 4.0.0 to 4.1.3, Helm will install plugins missing provenance (
fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, fast-jwt does not validate the crit (C
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the han
OpenClaw before 2026.4.8 contains an approval-timeout fallback mechanism that bypasses strictInlineEval explicit-approva
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4
rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent host
OpenClaw before 2026.3.31 contains a decompression bomb vulnerability in image processing that fails to properly enforce
Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that al
IGEL OS 12 before 12.9.0, 12.8.3 LTS and IGEL OS 11 before 11.11.150 contain a secure boot bypass vulnerability in the G
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by
pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections
OpenClaw before 2026.4.25 contains a scope containment bypass vulnerability in device re-pairing that allows authenticat
pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in version 0.14.0 and prior to version 26.0.0, if a u
free5GC is an open-source implementation of the 5G core network. In versions 4.2.1 and below of the UDR service, the PUT
### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing a
An administrator may attempt to block all networks by specifying "\*" or "all" as the network identifier. However, these
An administrator may attempt to block all traffic by configuring a pass filter with an empty table. However, in UBR, an
OpenClaw before 2026.3.31 contains a fail-open vulnerability in the plugin installation flow where security scan failure
OpenClaw before 2026.5.6 contains an improper access control vulnerability in Mattermost event handlers that fails to va
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.9, OCI
OpenClaw before 2026.3.11 contains a credential fallback vulnerability where unavailable local gateway.auth.token and ga
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m
Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 m
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security L
NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate
Frequently Asked Questions
What is CWE-636?
CWE-636 (CWE-636) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-636?
There are 34 CVE records associated with CWE-636 in our database. Of these, 3 are critical severity, 12 are high severity, and 12 are medium severity.
How can I protect against CWE-636 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-636 using AI-powered security agents.
Detect CWE-636 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-636 vulnerabilities across your infrastructure.
Get Started