CWE-614 · 64 kayıt
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Bu sınıftaki CVE’ler
64 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2025-8037İstismar yok | Nameless cookies shadow secure cookiesmozilla · firefox · CWE-614 | Kritik9,1 | — | %0,2 | 22 Tem 2025 |
35İzleyin | CVE-2026-53661İstismar yok | boruta-server sent sensitive session cookies without the Secure attributemalach-it · boruta-server · CWE-614 | Yüksek8,8 | — | %0,3 | 11 Haz 2026 |
35İzleyin | CVE-2026-46398İstismar yok | HAX CMS Missing Secure Flag on Cookiehaxtheweb · haxcms-php · CWE-614 | Yüksek8,8 | — | %0,3 | 5 Haz 2026 |
34İzleyin | CVE-2025-0479İstismar yok | Security Misconfiguration Vulnerability in CP Plus Routercp plus · cp-xr-de21-s router · CWE-614 | Yüksek8,6 | — | %0,4 | 20 Oca 2025 |
34İzleyin | CVE-2025-53757İstismar yok | Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Routerdigisol · xpon onu wi-fi router (dg-gr6821ac) · CWE-614 | Yüksek8,7 | — | %0,3 | 16 Tem 2025 |
32İzleyin | CVE-2020-27651İstismar yok | Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easisynology · router manager · CWE-614 | Yüksek8,1 | — | %0,8 | 29 Eki 2020 |
30İzleyin | CVE-2022-25151İstismar yok | ITarian - Session cookie not protected by HttpOnly flagitarian · on-premise · CWE-614 | Yüksek7,5 | — | %0,8 | 9 Haz 2022 |
30İzleyin | CVE-2022-3174İstismar yok | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffwebikus-soft · rdiffweb · CWE-614 | Yüksek7,5 | — | %0,7 | 13 Eyl 2022 |
30İzleyin | CVE-2018-25060İstismar yok | Macaron csrf csrf.go missing secure attributego-macaron · csrf · CWE-614 | Yüksek7,5 | — | %0,5 | 30 Ara 2022 |
30İzleyin | CVE-2022-4409İstismar yok | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaqphpmyfaq · phpmyfaq · CWE-614 | Yüksek7,5 | — | %0,4 | 11 Ara 2022 |
30İzleyin | CVE-2024-10718İstismar yok | Cookie without Secure attribute in phpipam/phpipamphpipam · phpipam · CWE-614 | Yüksek7,5 | — | %0,3 | 20 Mar 2025 |
30İzleyin | CVE-2024-2493İstismar yok | Session Hijacking Vulnerability in Hitachi Ops Center Analyzerhitachi · hitachi ops center analyzer · CWE-614 | Yüksek7,5 | — | %0,3 | 23 Nis 2024 |
30İzleyin | CVE-2026-57948İstismar yok | Pinpoint - Insecure Session Cookie Attributes in pinpointJwtpinpoint-apm · pinpoint · CWE-614 | Yüksek7,6 | — | %0,2 | 29 Haz 2026 |
30İzleyin | CVE-2025-52632İstismar yok | HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerabilityhcltech · aion · CWE-614 | Yüksek7,5 | — | %0,1 | 10 Eki 2025 |
29İzleyin | CVE-2026-22617İstismar yok | Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the ceaton · intelligent power protector · CWE-614 | Yüksek7,4 | — | %0,2 | 16 Nis 2026 |
27İzleyin | CVE-2021-3882İstismar yok | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmbledgersmb · ledgersmb · CWE-614 | Orta6,8 | — | %1,1 | 14 Eki 2021 |
27İzleyin | CVE-2024-35211İstismar yok | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2).siemens · sinec traffic analyzer · CWE-614 | Orta6,8 | — | %0,2 | 11 Haz 2024 |
27İzleyin | CVE-2024-41684İstismar yok | Cookie Without Secure Flag Set Vulnerabilitysyrotech · sy-gpon-1110-wdont firmware · CWE-614 | Orta6,9 | — | %0,2 | 26 Tem 2024 |
27İzleyin | CVE-2025-24390İstismar yok | Missing Cookie Flagsotrs ag · otrs · CWE-614 | Orta6,8 | — | %0,2 | 27 Oca 2025 |
27İzleyin | CVE-2024-58317İstismar yok | Kentico Xperience <= 13.0.164 Cookie Security Configurationkentico · xperience · CWE-614 | Orta6,9 | — | %0,2 | 18 Ara 2025 |
26İzleyin | CVE-2022-24045İstismar yok | A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PXsiemens · desigo dxr2 firmware · CWE-614 | Orta6,5 | — | %0,6 | 20 May 2022 |
26İzleyin | CVE-2021-27764İstismar yok | HCL BigFix WebUI Cookie missing attributeshcltech · bigfix webui · CWE-614 | Orta6,5 | — | %0,6 | 6 May 2022 |
26İzleyin | CVE-2022-4683İstismar yok | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in usememos/memosusememos · memos · CWE-614 | Orta6,5 | — | %0,4 | 23 Ara 2022 |
26İzleyin | CVE-2025-27450İstismar yok | The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.endress · meac300-fnade4 firmware · CWE-614 | Orta6,5 | — | %0,3 | 3 Tem 2025 |
26İzleyin | CVE-2024-28770İstismar yok | IBM Security Directory Integrator information disclosureibm · security directory integrator · CWE-614 | Orta6,5 | — | %0,2 | 26 Oca 2025 |
- CVE-2025-803736İzleyin
Nameless cookies shadow secure cookies
KritikCVSS 9,1İstismar yokEPSS %0mozilla · firefox22 Tem 2025
- CVE-2026-5366135İzleyin
boruta-server sent sensitive session cookies without the Secure attribute
YüksekCVSS 8,8İstismar yokEPSS %0malach-it · boruta-server11 Haz 2026
- CVE-2026-4639835İzleyin
HAX CMS Missing Secure Flag on Cookie
YüksekCVSS 8,8İstismar yokEPSS %0haxtheweb · haxcms-php5 Haz 2026
- CVE-2025-047934İzleyin
Security Misconfiguration Vulnerability in CP Plus Router
YüksekCVSS 8,6İstismar yokEPSS %0cp plus · cp-xr-de21-s router20 Oca 2025
- CVE-2025-5375734İzleyin
Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Router
YüksekCVSS 8,7İstismar yokEPSS %0digisol · xpon onu wi-fi router (dg-gr6821ac)16 Tem 2025
- CVE-2020-2765132İzleyin
Synology Router Manager (SRM) before 1.2.4-8081 does not set the Secure flag for the session cookie in an HTTPS session, which makes it easi
YüksekCVSS 8,1İstismar yokEPSS %1synology · router manager29 Eki 2020
- CVE-2022-2515130İzleyin
ITarian - Session cookie not protected by HttpOnly flag
YüksekCVSS 7,5İstismar yokEPSS %1itarian · on-premise9 Haz 2022
- CVE-2022-317430İzleyin
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ikus060/rdiffweb
YüksekCVSS 7,5İstismar yokEPSS %1ikus-soft · rdiffweb13 Eyl 2022
- CVE-2018-2506030İzleyin
Macaron csrf csrf.go missing secure attribute
YüksekCVSS 7,5İstismar yokEPSS %1go-macaron · csrf30 Ara 2022
- CVE-2022-440930İzleyin
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in thorsten/phpmyfaq
YüksekCVSS 7,5İstismar yokEPSS %0phpmyfaq · phpmyfaq11 Ara 2022
- CVE-2024-1071830İzleyin
Cookie without Secure attribute in phpipam/phpipam
YüksekCVSS 7,5İstismar yokEPSS %0phpipam · phpipam20 Mar 2025
- CVE-2024-249330İzleyin
Session Hijacking Vulnerability in Hitachi Ops Center Analyzer
YüksekCVSS 7,5İstismar yokEPSS %0hitachi · hitachi ops center analyzer23 Nis 2024
- CVE-2026-5794830İzleyin
Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
YüksekCVSS 7,6İstismar yokEPSS %0pinpoint-apm · pinpoint29 Haz 2026
- CVE-2025-5263230İzleyin
HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
YüksekCVSS 7,5İstismar yokEPSS %0hcltech · aion10 Eki 2025
- CVE-2026-2261729İzleyin
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the c
YüksekCVSS 7,4İstismar yokEPSS %0eaton · intelligent power protector16 Nis 2026
- CVE-2021-388227İzleyin
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in ledgersmb/ledgersmb
OrtaCVSS 6,8İstismar yokEPSS %1ledgersmb · ledgersmb14 Eki 2021
- CVE-2024-3521127İzleyin
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2).
OrtaCVSS 6,8İstismar yokEPSS %0siemens · sinec traffic analyzer11 Haz 2024
- CVE-2024-4168427İzleyin
Cookie Without Secure Flag Set Vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0syrotech · sy-gpon-1110-wdont firmware26 Tem 2024
- CVE-2025-2439027İzleyin
Missing Cookie Flags
OrtaCVSS 6,8İstismar yokEPSS %0otrs ag · otrs27 Oca 2025
- CVE-2024-5831727İzleyin
Kentico Xperience <= 13.0.164 Cookie Security Configuration
OrtaCVSS 6,9İstismar yokEPSS %0kentico · xperience18 Ara 2025
- CVE-2022-2404526İzleyin
A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.142.5-22), Desigo PXC3 (All versions < V01.21.142.4-18), Desigo PX
OrtaCVSS 6,5İstismar yokEPSS %1siemens · desigo dxr2 firmware20 May 2022
- CVE-2021-2776426İzleyin
HCL BigFix WebUI Cookie missing attributes
OrtaCVSS 6,5İstismar yokEPSS %1hcltech · bigfix webui6 May 2022
- CVE-2022-468326İzleyin
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in usememos/memos
OrtaCVSS 6,5İstismar yokEPSS %0usememos · memos23 Ara 2022
- CVE-2025-2745026İzleyin
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4.
OrtaCVSS 6,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2024-2877026İzleyin
IBM Security Directory Integrator information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0ibm · security directory integrator26 Oca 2025