Skip to content
Noroxi

CWE-565 · 61 records

Reliance on Cookies without Validation and Integrity Checking

CVEs in this class

61 records

  • PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

    HighCVSS 7.8KEVWeaponizedEPSS 96%

    paloaltonetworks · pan-osMay 13, 2026

  • CVE-2023-35885
    61This week

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

    CriticalCVSS 9.8Proof of conceptEPSS 75%

    mgt-commerce · cloudpanelJun 20, 2023

  • V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    v3chat · v3 chat profiles dating scriptDec 31, 2008

  • An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.

    CriticalCVSS 9.8No exploitEPSS 5%

    njhyst · hy511 firmwareJan 6, 2026

  • Linear eMerge 50P/5000P devices allow Authentication Bypass.

    CriticalCVSS 9.8No exploitEPSS 5%

    nortekcontrol · linear emerge 50p firmwareJul 2, 2019

  • An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo

    CriticalCVSS 9.8No exploitEPSS 4%

    unitrends · enterprise backupApr 12, 2017

  • EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

    CriticalCVSS 9.8No exploitEPSS 2%

    cdatatec · epon cpe-wifi devices firmwareJan 3, 2019

  • CVE-2018-5455
    39Monitor

    A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606

    CriticalCVSS 9.8No exploitEPSS 2%

    moxa · oncell g3110-hspa firmwareMar 5, 2018

  • CVE-2018-5190
    39Monitor

    PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo

    CriticalCVSS 9.8No exploitEPSS 1%

    picturespro · picturesproApr 17, 2018

  • UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

    CriticalCVSS 9.8No exploitEPSS 1%

    ucms project · ucmsSep 12, 2022

  • Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution

    CriticalCVSS 9.8No exploitEPSS 1%

    miyagawa · plack\Mar 25, 2026

  • JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    jayarsiech · jay login & registerDec 13, 2025

  • Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul

    CriticalCVSS 9.8No exploitEPSS 1%

    ruijie · rg-nbr700gw firmwareMar 29, 2024

  • Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking

    CriticalCVSS 9.8No exploitEPSS 1%

    socomec · modulys gp firmwareSep 18, 2023

  • CVE-2025-2395
    39Monitor

    e-Excellence U-Office Force - Improper Authentication

    CriticalCVSS 9.8No exploitEPSS 1%

    edetw · u-office forceMar 17, 2025

  • CVE-2024-0947
    39Monitor

    Cookies Manipulation in Talya Informatics' Elektraweb

    CriticalCVSS 9.8No exploitEPSS 0%

    talya informatics · elektrawebJun 27, 2024

  • Improperly constrained session cookies in Zoom Client for Meetings

    CriticalCVSS 9.1No exploitEPSS 3%

    zoom · meetingsMay 18, 2022

  • CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum

    CriticalCVSS 9.3No exploitEPSS 1%

    dianping · catSep 3, 2026

  • CVE-2017-6896
    36Monitor

    Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a

    HighCVSS 8.8Proof of conceptEPSS 4%

    digisol · dg-hr1400 router firmwareMar 14, 2017

  • CVE-2012-5631
    36Monitor

    ipa 3.0 does not properly check server identity before sending credential containing cookies

    HighCVSS 8.8No exploitEPSS 2%

    freeipa · freeipaNov 25, 2019

  • Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity

    CriticalCVSS 9.1No exploitEPSS 1%

    apache · apache-airflow-providers-keycloakSep 16, 2026

  • A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu

    HighCVSS 8.1No exploitEPSS 8%

    fortinet · fortiwebDec 9, 2025

  • Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.

    HighCVSS 8.8No exploitEPSS 1%

    zabbix · zabbix serverDec 18, 2023

  • CVE-2024-9970
    35Monitor

    NewType FlowMaster BPM Plus - Privilege Escalation

    HighCVSS 8.8No exploitEPSS 1%

    newtype · flowmaster bpm plusOct 15, 2024

  • CVE-2026-5130
    35Monitor

    Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation

    HighCVSS 8.8No exploitEPSS 1%

    jhimross · debugger & troubleshooterMar 30, 2026

All vulnerability classes