CWE-565 · 61 records
Reliance on Cookies without Validation and Integrity Checking
CVEs in this class
61 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2026-0257Weaponized | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitiespaloaltonetworks · pan-os · CWE-565 | High7.8 | KEV | 96.4% | May 13, 2026 |
61This week | CVE-2023-35885Proof of concept | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.mgt-commerce · cloudpanel · CWE-565 | Critical9.8 | — | 74.9% | Jun 20, 2023 |
41Plan | CVE-2008-5784Proof of concept | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin v3chat · v3 chat profiles dating script · CWE-565 | Critical9.8 | — | 7.1% | Dec 31, 2008 |
41Plan | CVE-2025-65212No exploit | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.njhyst · hy511 firmware · CWE-565 | Critical9.8 | — | 5.2% | Jan 6, 2026 |
40Plan | CVE-2019-7266No exploit | Linear eMerge 50P/5000P devices allow Authentication Bypass.nortekcontrol · linear emerge 50p firmware · CWE-565 | Critical9.8 | — | 4.6% | Jul 2, 2019 |
40Plan | CVE-2017-7279No exploit | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Critical9.8 | — | 4.4% | Apr 12, 2017 |
40Plan | CVE-2018-20512No exploit | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.cdatatec · epon cpe-wifi devices firmware · CWE-565 | Critical9.8 | — | 1.8% | Jan 3, 2019 |
39Monitor | CVE-2018-5455No exploit | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606moxa · oncell g3110-hspa firmware · CWE-565 | Critical9.8 | — | 1.6% | Mar 5, 2018 |
39Monitor | CVE-2018-5190No exploit | PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coopicturespro · picturespro · CWE-565 | Critical9.8 | — | 1.4% | Apr 17, 2018 |
39Monitor | CVE-2022-38297No exploit | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.ucms project · ucms · CWE-565 | Critical9.8 | — | 1.2% | Sep 12, 2022 |
39Monitor | CVE-2014-125112No exploit | Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code executionmiyagawa · plack\ · CWE-565 | Critical9.8 | — | 0.8% | Mar 25, 2026 |
39Monitor | CVE-2025-14440Proof of concept | JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookiejayarsiech · jay login & register · CWE-565 | Critical9.8 | — | 0.8% | Dec 13, 2025 |
39Monitor | CVE-2024-28288No exploit | Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulruijie · rg-nbr700gw firmware · CWE-565 | Critical9.8 | — | 0.7% | Mar 29, 2024 |
39Monitor | CVE-2023-41084No exploit | Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checkingsocomec · modulys gp firmware · CWE-565 | Critical9.8 | — | 0.7% | Sep 18, 2023 |
39Monitor | CVE-2025-2395No exploit | e-Excellence U-Office Force - Improper Authenticationedetw · u-office force · CWE-565 | Critical9.8 | — | 0.6% | Mar 17, 2025 |
39Monitor | CVE-2024-0947No exploit | Cookies Manipulation in Talya Informatics' Elektrawebtalya informatics · elektraweb · CWE-565 | Critical9.8 | — | 0.5% | Jun 27, 2024 |
37Monitor | CVE-2022-22785No exploit | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Critical9.1 | — | 3.5% | May 18, 2022 |
37Monitor | CVE-2026-85181No exploit | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksumdianping · cat · CWE-565 | Critical9.3 | — | 0.7% | Sep 3, 2026 |
36Monitor | CVE-2017-6896Proof of concept | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to adigisol · dg-hr1400 router firmware · CWE-565 | High8.8 | — | 3.7% | Mar 14, 2017 |
36Monitor | CVE-2012-5631No exploit | ipa 3.0 does not properly check server identity before sending credential containing cookiesfreeipa · freeipa · CWE-565 | High8.8 | — | 1.8% | Nov 25, 2019 |
36Monitor | CVE-2026-76186No exploit | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identityapache · apache-airflow-providers-keycloak · CWE-565 | Critical9.1 | — | 0.8% | Sep 16, 2026 |
35Monitor | CVE-2025-64447No exploit | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throufortinet · fortiweb · CWE-565 | High8.1 | — | 8.4% | Dec 9, 2025 |
35Monitor | CVE-2023-32725No exploit | Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.zabbix · zabbix server · CWE-565 | High8.8 | — | 0.8% | Dec 18, 2023 |
35Monitor | CVE-2024-9970No exploit | NewType FlowMaster BPM Plus - Privilege Escalationnewtype · flowmaster bpm plus · CWE-565 | High8.8 | — | 0.6% | Oct 15, 2024 |
35Monitor | CVE-2026-5130No exploit | Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulationjhimross · debugger & troubleshooter · CWE-565 | High8.8 | — | 0.6% | Mar 30, 2026 |
- CVE-2026-025790Now
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
HighCVSS 7.8KEVWeaponizedEPSS 96%paloaltonetworks · pan-osMay 13, 2026
- CVE-2023-3588561This week
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
CriticalCVSS 9.8Proof of conceptEPSS 75%mgt-commerce · cloudpanelJun 20, 2023
- CVE-2008-578441Plan
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin
CriticalCVSS 9.8Proof of conceptEPSS 7%v3chat · v3 chat profiles dating scriptDec 31, 2008
- CVE-2025-6521241Plan
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.
CriticalCVSS 9.8No exploitEPSS 5%njhyst · hy511 firmwareJan 6, 2026
- CVE-2019-726640Plan
Linear eMerge 50P/5000P devices allow Authentication Bypass.
CriticalCVSS 9.8No exploitEPSS 5%nortekcontrol · linear emerge 50p firmwareJul 2, 2019
- CVE-2017-727940Plan
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
CriticalCVSS 9.8No exploitEPSS 4%unitrends · enterprise backupApr 12, 2017
- CVE-2018-2051240Plan
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
CriticalCVSS 9.8No exploitEPSS 2%cdatatec · epon cpe-wifi devices firmwareJan 3, 2019
- CVE-2018-545539Monitor
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606
CriticalCVSS 9.8No exploitEPSS 2%moxa · oncell g3110-hspa firmwareMar 5, 2018
- CVE-2018-519039Monitor
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo
CriticalCVSS 9.8No exploitEPSS 1%picturespro · picturesproApr 17, 2018
- CVE-2022-3829739Monitor
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
CriticalCVSS 9.8No exploitEPSS 1%ucms project · ucmsSep 12, 2022
- CVE-2014-12511239Monitor
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
CriticalCVSS 9.8No exploitEPSS 1%miyagawa · plack\Mar 25, 2026
- CVE-2025-1444039Monitor
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
CriticalCVSS 9.8Proof of conceptEPSS 1%jayarsiech · jay login & registerDec 13, 2025
- CVE-2024-2828839Monitor
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul
CriticalCVSS 9.8No exploitEPSS 1%ruijie · rg-nbr700gw firmwareMar 29, 2024
- CVE-2023-4108439Monitor
Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking
CriticalCVSS 9.8No exploitEPSS 1%socomec · modulys gp firmwareSep 18, 2023
- CVE-2025-239539Monitor
e-Excellence U-Office Force - Improper Authentication
CriticalCVSS 9.8No exploitEPSS 1%edetw · u-office forceMar 17, 2025
- CVE-2024-094739Monitor
Cookies Manipulation in Talya Informatics' Elektraweb
CriticalCVSS 9.8No exploitEPSS 0%talya informatics · elektrawebJun 27, 2024
- CVE-2022-2278537Monitor
Improperly constrained session cookies in Zoom Client for Meetings
CriticalCVSS 9.1No exploitEPSS 3%zoom · meetingsMay 18, 2022
- CVE-2026-8518137Monitor
CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
CriticalCVSS 9.3No exploitEPSS 1%dianping · catSep 3, 2026
- CVE-2017-689636Monitor
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a
HighCVSS 8.8Proof of conceptEPSS 4%digisol · dg-hr1400 router firmwareMar 14, 2017
- CVE-2012-563136Monitor
ipa 3.0 does not properly check server identity before sending credential containing cookies
HighCVSS 8.8No exploitEPSS 2%freeipa · freeipaNov 25, 2019
- CVE-2026-7618636Monitor
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
CriticalCVSS 9.1No exploitEPSS 1%apache · apache-airflow-providers-keycloakSep 16, 2026
- CVE-2025-6444735Monitor
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu
HighCVSS 8.1No exploitEPSS 8%fortinet · fortiwebDec 9, 2025
- CVE-2023-3272535Monitor
Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.
HighCVSS 8.8No exploitEPSS 1%zabbix · zabbix serverDec 18, 2023
- CVE-2024-997035Monitor
NewType FlowMaster BPM Plus - Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%newtype · flowmaster bpm plusOct 15, 2024
- CVE-2026-513035Monitor
Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation
HighCVSS 8.8No exploitEPSS 1%jhimross · debugger & troubleshooterMar 30, 2026