CWE-358: CWE-358

28
Total CVEs
4
Critical
9
High
6.6
Avg CVSS

Yearly Trend

2026
6
2025
14
2024
5
2023
2
2022
1

Top Affected Vendors

1 Fortinet 4
2 Apple 3
3 Navercorp 3
4 Yokogawa 3
5 Google 2
6 Huawei 2
7 Ibm 1
8 Hcltech 1
9 Zoom 1
10 Bullwall 1

All CWE-358 CVEs (28)

CVE-2022-25152
9.9

CVE-2022-25152 is a critical vulnerability in the ITarian platform that allows authenticated users to bypass mandatory approval processes and execute ...

Jun 9, 2022
CVE-2025-66603
9.8

The OPTIONS method vulnerability in Yokogawa FAST/TOOLS web servers exposes HTTP method information that could aid attackers in reconnaissance and sub...

Feb 9, 2026
CVE-2025-62583
9.8

This vulnerability in Whale Browser allows attackers to escape iframe sandbox restrictions in dual-tab environments, potentially enabling cross-origin...

Oct 16, 2025
CVE-2025-69234
9.1

This vulnerability in Whale browser allows attackers to escape iframe sandbox restrictions in sidebar environments, potentially executing malicious co...

Dec 30, 2025
CVE-2026-1486
8.8

This vulnerability allows attackers to bypass disabled Identity Provider (IdP) checks in Keycloak's JWT authorization grant flow. An attacker with a d...

Feb 9, 2026
CVE-2023-28601
8.3

This vulnerability in Zoom for Windows allows a malicious user to manipulate protected memory buffers, potentially compromising the integrity of the Z...

Jun 13, 2023
CVE-2024-27842
7.8

This is a macOS kernel privilege escalation vulnerability that allows a malicious application to execute arbitrary code with kernel-level privileges. ...

May 14, 2024
CVE-2024-25545
7.8

This vulnerability in Weave Desktop v7.78.10 allows a local attacker to execute arbitrary code by exploiting the nwjs framework component with a craft...

Apr 12, 2024
CVE-2025-62585
7.5

This vulnerability allows attackers to bypass Content Security Policy (CSP) protections in Whale browser by exploiting a specific scheme in dual-tab e...

Oct 16, 2025
CVE-2025-59147
7.5

CVE-2025-59147 is a detection bypass vulnerability in Suricata where crafted traffic with multiple SYN packets containing different sequence numbers w...

Oct 1, 2025
CVE-2023-40445
7.5

This vulnerability in iOS/iPadOS prevents devices from properly locking, allowing unauthorized physical access to unlocked devices. It affects users o...

Oct 25, 2023
CVE-2025-58308
7.3

This vulnerability involves improper security checks in a call module, allowing attackers to bypass intended restrictions. Successful exploitation cou...

Nov 28, 2025
CVE-2025-32086
7.2

This vulnerability in Intel Xeon 6 processors allows a privileged user to bypass security checks in DDRIO configuration when using Intel SGX or TDX te...

Aug 12, 2025
CVE-2021-26105
6.8

This CVE describes a stack-based buffer overflow vulnerability in FortiSandbox's profile parser that allows authenticated attackers to execute arbitra...

Mar 24, 2025
CVE-2024-5500
6.5

This vulnerability in Google Chrome allows attackers to bypass navigation restrictions through a crafted HTML page, potentially redirecting users to m...

Jul 16, 2024
CVE-2025-66601
6.1

A content sniffing vulnerability in Yokogawa's FAST/TOOLS software allows attackers to execute malicious scripts by exploiting unspecified MIME types....

Feb 9, 2026
CVE-2025-66607
5.3

This vulnerability in Yokogawa FAST/TOOLS involves insecure response header settings that could allow attackers to redirect users to malicious website...

Feb 9, 2026
CVE-2025-66323
5.3

This vulnerability involves improper security checks in Huawei's card module, allowing attackers to potentially disrupt system availability. It affect...

Dec 8, 2025
CVE-2024-55599
5.3

This vulnerability allows remote unauthenticated attackers to bypass DNS filtering protections on Fortinet devices when Apple devices are used. It aff...

Jul 8, 2025
CVE-2025-43262
5.1

A permissions bypass vulnerability in macOS allows USB accessories connected during boot to circumvent USB Restricted Mode security controls. This aff...

Sep 15, 2025
CVE-2020-9295
4.7

This vulnerability affects Fortinet's antivirus engine in FortiOS and FortiClient, causing delayed detection of malicious files within malformed RAR a...

Mar 17, 2025
CVE-2025-13333
4.4

IBM WebSphere Application Server versions 9.0 and 8.5 have a security weakness in system administration security settings that could allow attackers t...

Feb 17, 2026
CVE-2025-62002
4.3

This vulnerability in BullWall Ransomware Containment allows authenticated attackers to bypass detection by encrypting a single file when detection th...

Dec 18, 2025
CVE-2025-10457
4.3

This vulnerability allows attackers to spoof BLE connection responses to devices running vulnerable Zephyr RTOS versions. By sending unsolicited conne...

Sep 19, 2025
CVE-2024-33510
4.3

This CVE describes an injection vulnerability in Fortinet's SSL-VPN web user interface that could allow remote unauthenticated attackers to perform ph...

Nov 12, 2024
CVE-2024-7003
4.3

This vulnerability in Google Chrome's FedCM (Federated Credential Management) implementation allows attackers to spoof UI elements through specific us...

Aug 6, 2024
CVE-2025-31969
4.0

HCL Unica Platform has a misconfigured Content Security Policy (CSP) that could allow attackers to load malicious resources in users' browsers. This c...

Oct 12, 2025
CVE-2025-66600
N/A

FAST/TOOLS industrial control system software lacks HSTS configuration, allowing attackers to perform MITM attacks and intercept web communications. T...

Feb 9, 2026

About CWE-358 (CWE-358)

Our database tracks 28 CVEs classified as CWE-358, with 4 rated critical and 9 rated high severity. The average CVSS score for CWE-358 vulnerabilities is 6.6.

External reference: View CWE-358 on MITRE CWE →

Monitor CWE-358 Vulnerabilities

Get alerted when new CWE-358 CVEs affect your infrastructure.

Start Monitoring Free