Skip to content
Noroxi

CWE-602 · 161 records

Client-Side Enforcement of Server-Side Security

CVEs in this class

161 records

  • In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

    CriticalCVSS 10.0No exploitEPSS 1%

    jetbrains · intellij ideaJul 23, 2026

  • Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback

    CriticalCVSS 10.0No exploitEPSS 0%

    cal · cal.comJan 13, 2026

  • Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend

    CriticalCVSS 10.0No exploitEPSS 0%

    sovity · dataspace-portalMay 8, 2026

  • mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to adminis

    CriticalCVSS 9.8No exploitEPSS 2%

    mjobtime · mjobtimeDec 1, 2025

  • Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional

    CriticalCVSS 9.8No exploitEPSS 1%

    efficientlab · workexaminer professionalOct 21, 2025

  • Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-

    CriticalCVSS 9.8No exploitEPSS 1%

    printerlogic · vasion printMar 5, 2025

  • A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.

    CriticalCVSS 9.8No exploitEPSS 1%

    tecno · com.transsion.applockDec 12, 2024

  • CVE-2023-0750
    39Monitor

    Yellowbrik PEC-1864 authentication bypass

    CriticalCVSS 9.8No exploitEPSS 0%

    lynx-technik · yellobrik pec 1864 firmwareApr 6, 2023

  • The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload.

    CriticalCVSS 9.8No exploitEPSS 0%

    multiple file upload project · multiple file uploadMay 5, 2025

  • Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability

    CriticalCVSS 9.6No exploitEPSS 1%

    cisco · unified contact center expressJan 14, 2022

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    CriticalCVSS 9.4No exploitEPSS 1%

    siemens · ruggedcom rox mx5000May 13, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    CriticalCVSS 9.4No exploitEPSS 1%

    siemens · ruggedcom rox mx5000May 13, 2025

  • A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    CriticalCVSS 9.4No exploitEPSS 1%

    siemens · ruggedcom rox mx5000May 13, 2025

  • A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0

    HighCVSS 8.8Proof of conceptEPSS 3%

    fortinet · fortianalyzerNov 12, 2024

  • CVE-2022-1525
    36Monitor

    Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security

    CriticalCVSS 9.1No exploitEPSS 1%

    cognex · 3d-a1000 dimensioning system firmwareSep 6, 2022

  • Priority – CWE-602: Client-Side Enforcement of Server-Side Security

    CriticalCVSS 9.1No exploitEPSS 0%

    priority · portal generator addon to priority erp (developed by soft solutions)Aug 13, 2026

  • Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)

    CriticalCVSS 9.0No exploitEPSS 0%

    budibase · budibaseMar 9, 2026

  • It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset reque

    HighCVSS 8.8No exploitEPSS 1%

    keycloak · keycloakFeb 21, 2018

  • CVE-2024-9844
    35Monitor

    Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticat

    HighCVSS 8.8No exploitEPSS 1%

    ivanti · connect secureDec 10, 2024

  • A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2

    HighCVSS 8.8No exploitEPSS 1%

    fortinet · fortisandboxMay 14, 2024

  • Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie

    HighCVSS 8.8No exploitEPSS 1%

    deltaww · diaenergieMar 21, 2024

  • Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a cra

    HighCVSS 8.8No exploitEPSS 0%

    google · chromeJun 30, 2026

  • An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26

    HighCVSS 8.9No exploitEPSS 0%

    Oct 6, 2025

  • IBM Aspera Faspex data modification

    HighCVSS 8.8No exploitEPSS 0%

    ibm · aspera faspexMay 22, 2025

  • Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation

    HighCVSS 8.8No exploitEPSS 0%

    google · chromeJun 30, 2026

All vulnerability classes