İçeriğe atla
Noroxi

CWE-614 · 64 kayıt

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute

Bu sınıftaki CVE’ler

64 kayıt

  • CVE-2025-8037
    36İzleyin

    Nameless cookies shadow secure cookies

    KritikCVSS 9,1İstismar yokEPSS %0

    mozilla · firefox22 Tem 2025

  • CVE-2026-53661
    35İzleyin

    boruta-server sent sensitive session cookies without the Secure attribute

    YüksekCVSS 8,8İstismar yokEPSS %0

    malach-it · boruta-server11 Haz 2026

  • CVE-2026-46398
    35İzleyin

    HAX CMS Missing Secure Flag on Cookie

    YüksekCVSS 8,8İstismar yokEPSS %0

    haxtheweb · haxcms-php5 Haz 2026

  • CVE-2025-0479
    34İzleyin

    Security Misconfiguration Vulnerability in CP Plus Router

    YüksekCVSS 8,6İstismar yokEPSS %0

    cp plus · cp-xr-de21-s router20 Oca 2025

  • CVE-2025-53757
    34İzleyin

    Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Router

    YüksekCVSS 8,7İstismar yokEPSS %0

    digisol · xpon onu wi-fi router (dg-gr6821ac)16 Tem 2025

  • CVE-2020-27651
    32İzleyin

    Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easi

    YüksekCVSS 8,1İstismar yokEPSS %1

    synology · router manager29 Eki 2020

  • CVE-2022-25151
    30İzleyin

    ITarian - Session cookie not protected by HttpOnly flag

    YüksekCVSS 7,5İstismar yokEPSS %1

    itarian · on-premise9 Haz 2022

  • CVE-2022-3174
    30İzleyin

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb

    YüksekCVSS 7,5İstismar yokEPSS %1

    ikus-soft · rdiffweb13 Eyl 2022

  • CVE-2018-25060
    30İzleyin

    Macaron csrf csrf.go missing secure attribute

    YüksekCVSS 7,5İstismar yokEPSS %1

    go-macaron · csrf30 Ara 2022

  • CVE-2022-4409
    30İzleyin

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq

    YüksekCVSS 7,5İstismar yokEPSS %0

    phpmyfaq · phpmyfaq11 Ara 2022

  • CVE-2024-10718
    30İzleyin

    Cookie without Secure attribute in phpipam/phpipam

    YüksekCVSS 7,5İstismar yokEPSS %0

    phpipam · phpipam20 Mar 2025

  • CVE-2024-2493
    30İzleyin

    Session Hijacking Vulnerability in Hitachi Ops Center Analyzer

    YüksekCVSS 7,5İstismar yokEPSS %0

    hitachi · hitachi ops center analyzer23 Nis 2024

  • CVE-2026-57948
    30İzleyin

    Pinpoint - Insecure Session Cookie Attributes in pinpointJwt

    YüksekCVSS 7,6İstismar yokEPSS %0

    pinpoint-apm · pinpoint29 Haz 2026

  • CVE-2025-52632
    30İzleyin

    HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability

    YüksekCVSS 7,5İstismar yokEPSS %0

    hcltech · aion10 Eki 2025

  • CVE-2026-22617
    29İzleyin

    Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the c

    YüksekCVSS 7,4İstismar yokEPSS %0

    eaton · intelligent power protector16 Nis 2026

  • CVE-2021-3882
    27İzleyin

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmb

    OrtaCVSS 6,8İstismar yokEPSS %1

    ledgersmb · ledgersmb14 Eki 2021

  • CVE-2024-35211
    27İzleyin

    A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2).

    OrtaCVSS 6,8İstismar yokEPSS %0

    siemens · sinec traffic analyzer11 Haz 2024

  • CVE-2024-41684
    27İzleyin

    Cookie Without Secure Flag Set Vulnerability

    OrtaCVSS 6,9İstismar yokEPSS %0

    syrotech · sy-gpon-1110-wdont firmware26 Tem 2024

  • CVE-2025-24390
    27İzleyin

    Missing Cookie Flags

    OrtaCVSS 6,8İstismar yokEPSS %0

    otrs ag · otrs27 Oca 2025

  • CVE-2024-58317
    27İzleyin

    Kentico Xperience <= 13.0.164 Cookie Security Configuration

    OrtaCVSS 6,9İstismar yokEPSS %0

    kentico · xperience18 Ara 2025

  • CVE-2022-24045
    26İzleyin

    A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PX

    OrtaCVSS 6,5İstismar yokEPSS %1

    siemens · desigo dxr2 firmware20 May 2022

  • CVE-2021-27764
    26İzleyin

    HCL BigFix WebUI Cookie missing attributes

    OrtaCVSS 6,5İstismar yokEPSS %1

    hcltech · bigfix webui6 May 2022

  • CVE-2022-4683
    26İzleyin

    Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in usememos/memos

    OrtaCVSS 6,5İstismar yokEPSS %0

    usememos · memos23 Ara 2022

  • CVE-2025-27450
    26İzleyin

    The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.

    OrtaCVSS 6,5İstismar yokEPSS %0

    endress · meac300-fnade4 firmware3 Tem 2025

  • CVE-2024-28770
    26İzleyin

    IBM Security Directory Integrator information disclosure

    OrtaCVSS 6,5İstismar yokEPSS %0

    ibm · security directory integrator26 Oca 2025

Tüm zafiyet sınıfları