CWE-565 · 61 kayıt
Reliance on Cookies without Validation and Integrity Checking
Bu sınıftaki CVE’ler
61 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
90Hemen | CVE-2026-0257Silahlaştırılmış | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitiespaloaltonetworks · pan-os · CWE-565 | Yüksek7,8 | KEV | %96,4 | 13 May 2026 |
61Bu hafta | CVE-2023-35885Kavram kanıtı | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.mgt-commerce · cloudpanel · CWE-565 | Kritik9,8 | — | %74,9 | 20 Haz 2023 |
41Planlayın | CVE-2008-5784Kavram kanıtı | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin v3chat · v3 chat profiles dating script · CWE-565 | Kritik9,8 | — | %7,1 | 31 Ara 2008 |
41Planlayın | CVE-2025-65212İstismar yok | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.njhyst · hy511 firmware · CWE-565 | Kritik9,8 | — | %5,2 | 6 Oca 2026 |
40Planlayın | CVE-2019-7266İstismar yok | Linear eMerge 50P/5000P devices allow Authentication Bypass.nortekcontrol · linear emerge 50p firmware · CWE-565 | Kritik9,8 | — | %4,6 | 2 Tem 2019 |
40Planlayın | CVE-2017-7279İstismar yok | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Kritik9,8 | — | %4,4 | 12 Nis 2017 |
40Planlayın | CVE-2018-20512İstismar yok | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.cdatatec · epon cpe-wifi devices firmware · CWE-565 | Kritik9,8 | — | %1,8 | 3 Oca 2019 |
39İzleyin | CVE-2018-5455İstismar yok | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606moxa · oncell g3110-hspa firmware · CWE-565 | Kritik9,8 | — | %1,6 | 5 Mar 2018 |
39İzleyin | CVE-2018-5190İstismar yok | PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coopicturespro · picturespro · CWE-565 | Kritik9,8 | — | %1,4 | 17 Nis 2018 |
39İzleyin | CVE-2022-38297İstismar yok | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.ucms project · ucms · CWE-565 | Kritik9,8 | — | %1,3 | 12 Eyl 2022 |
39İzleyin | CVE-2014-125112İstismar yok | Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code executionmiyagawa · plack\ · CWE-565 | Kritik9,8 | — | %0,8 | 25 Mar 2026 |
39İzleyin | CVE-2025-14440Kavram kanıtı | JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookiejayarsiech · jay login & register · CWE-565 | Kritik9,8 | — | %0,8 | 13 Ara 2025 |
39İzleyin | CVE-2024-28288İstismar yok | Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulruijie · rg-nbr700gw firmware · CWE-565 | Kritik9,8 | — | %0,7 | 29 Mar 2024 |
39İzleyin | CVE-2023-41084İstismar yok | Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checkingsocomec · modulys gp firmware · CWE-565 | Kritik9,8 | — | %0,7 | 18 Eyl 2023 |
39İzleyin | CVE-2025-2395İstismar yok | e-Excellence U-Office Force - Improper Authenticationedetw · u-office force · CWE-565 | Kritik9,8 | — | %0,6 | 17 Mar 2025 |
39İzleyin | CVE-2024-0947İstismar yok | Cookies Manipulation in Talya Informatics' Elektrawebtalya informatics · elektraweb · CWE-565 | Kritik9,8 | — | %0,5 | 27 Haz 2024 |
37İzleyin | CVE-2022-22785İstismar yok | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Kritik9,1 | — | %3,5 | 18 May 2022 |
37İzleyin | CVE-2026-85181İstismar yok | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksumdianping · cat · CWE-565 | Kritik9,3 | — | %0,7 | 3 Eyl 2026 |
36İzleyin | CVE-2017-6896Kavram kanıtı | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to adigisol · dg-hr1400 router firmware · CWE-565 | Yüksek8,8 | — | %3,7 | 14 Mar 2017 |
36İzleyin | CVE-2012-5631İstismar yok | ipa 3.0 does not properly check server identity before sending credential containing cookiesfreeipa · freeipa · CWE-565 | Yüksek8,8 | — | %1,8 | 25 Kas 2019 |
36İzleyin | CVE-2026-76186İstismar yok | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identityapache · apache-airflow-providers-keycloak · CWE-565 | Kritik9,1 | — | %0,8 | 16 Eyl 2026 |
35İzleyin | CVE-2025-64447İstismar yok | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throufortinet · fortiweb · CWE-565 | Yüksek8,1 | — | %8,4 | 9 Ara 2025 |
35İzleyin | CVE-2023-32725İstismar yok | Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.zabbix · zabbix server · CWE-565 | Yüksek8,8 | — | %0,8 | 18 Ara 2023 |
35İzleyin | CVE-2024-9970İstismar yok | NewType FlowMaster BPM Plus - Privilege Escalationnewtype · flowmaster bpm plus · CWE-565 | Yüksek8,8 | — | %0,6 | 15 Eki 2024 |
35İzleyin | CVE-2026-5130İstismar yok | Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulationjhimross · debugger & troubleshooter · CWE-565 | Yüksek8,8 | — | %0,6 | 30 Mar 2026 |
- CVE-2026-025790Hemen
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %96paloaltonetworks · pan-os13 May 2026
- CVE-2023-3588561Bu hafta
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
KritikCVSS 9,8Kavram kanıtıEPSS %75mgt-commerce · cloudpanel20 Haz 2023
- CVE-2008-578441Planlayın
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin
KritikCVSS 9,8Kavram kanıtıEPSS %7v3chat · v3 chat profiles dating script31 Ara 2008
- CVE-2025-6521241Planlayın
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.
KritikCVSS 9,8İstismar yokEPSS %5njhyst · hy511 firmware6 Oca 2026
- CVE-2019-726640Planlayın
Linear eMerge 50P/5000P devices allow Authentication Bypass.
KritikCVSS 9,8İstismar yokEPSS %5nortekcontrol · linear emerge 50p firmware2 Tem 2019
- CVE-2017-727940Planlayın
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
KritikCVSS 9,8İstismar yokEPSS %4unitrends · enterprise backup12 Nis 2017
- CVE-2018-2051240Planlayın
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
KritikCVSS 9,8İstismar yokEPSS %2cdatatec · epon cpe-wifi devices firmware3 Oca 2019
- CVE-2018-545539İzleyin
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606
KritikCVSS 9,8İstismar yokEPSS %2moxa · oncell g3110-hspa firmware5 Mar 2018
- CVE-2018-519039İzleyin
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo
KritikCVSS 9,8İstismar yokEPSS %1picturespro · picturespro17 Nis 2018
- CVE-2022-3829739İzleyin
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
KritikCVSS 9,8İstismar yokEPSS %1ucms project · ucms12 Eyl 2022
- CVE-2014-12511239İzleyin
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
KritikCVSS 9,8İstismar yokEPSS %1miyagawa · plack\25 Mar 2026
- CVE-2025-1444039İzleyin
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
KritikCVSS 9,8Kavram kanıtıEPSS %1jayarsiech · jay login & register13 Ara 2025
- CVE-2024-2828839İzleyin
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul
KritikCVSS 9,8İstismar yokEPSS %1ruijie · rg-nbr700gw firmware29 Mar 2024
- CVE-2023-4108439İzleyin
Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking
KritikCVSS 9,8İstismar yokEPSS %1socomec · modulys gp firmware18 Eyl 2023
- CVE-2025-239539İzleyin
e-Excellence U-Office Force - Improper Authentication
KritikCVSS 9,8İstismar yokEPSS %1edetw · u-office force17 Mar 2025
- CVE-2024-094739İzleyin
Cookies Manipulation in Talya Informatics' Elektraweb
KritikCVSS 9,8İstismar yokEPSS %0talya informatics · elektraweb27 Haz 2024
- CVE-2022-2278537İzleyin
Improperly constrained session cookies in Zoom Client for Meetings
KritikCVSS 9,1İstismar yokEPSS %3zoom · meetings18 May 2022
- CVE-2026-8518137İzleyin
CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
KritikCVSS 9,3İstismar yokEPSS %1dianping · cat3 Eyl 2026
- CVE-2017-689636İzleyin
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a
YüksekCVSS 8,8Kavram kanıtıEPSS %4digisol · dg-hr1400 router firmware14 Mar 2017
- CVE-2012-563136İzleyin
ipa 3.0 does not properly check server identity before sending credential containing cookies
YüksekCVSS 8,8İstismar yokEPSS %2freeipa · freeipa25 Kas 2019
- CVE-2026-7618636İzleyin
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
KritikCVSS 9,1İstismar yokEPSS %1apache · apache-airflow-providers-keycloak16 Eyl 2026
- CVE-2025-6444735İzleyin
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu
YüksekCVSS 8,1İstismar yokEPSS %8fortinet · fortiweb9 Ara 2025
- CVE-2023-3272535İzleyin
Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.
YüksekCVSS 8,8İstismar yokEPSS %1zabbix · zabbix server18 Ara 2023
- CVE-2024-997035İzleyin
NewType FlowMaster BPM Plus - Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %1newtype · flowmaster bpm plus15 Eki 2024
- CVE-2026-513035İzleyin
Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation
YüksekCVSS 8,8İstismar yokEPSS %1jhimross · debugger & troubleshooter30 Mar 2026