Перейти к содержимому
Noroxi

CWE-565 · 61 записей

Reliance on Cookies without Validation and Integrity Checking

CVE этого класса

61 записей

  • CVE-2026-0257
    90Срочно

    PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

    ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 96 %

    paloaltonetworks · pan-os13 мая 2026 г.

  • CVE-2023-35885
    61На этой неделе

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

    КритическаяCVSS 9,8Proof of conceptEPSS 75 %

    mgt-commerce · cloudpanel20 июн. 2023 г.

  • CVE-2008-5784
    41В плане

    V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    v3chat · v3 chat profiles dating script31 дек. 2008 г.

  • CVE-2025-65212
    41В плане

    An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    njhyst · hy511 firmware6 янв. 2026 г.

  • CVE-2019-7266
    40В плане

    Linear eMerge 50P/5000P devices allow Authentication Bypass.

    КритическаяCVSS 9,8Эксплойта нетEPSS 5 %

    nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.

  • CVE-2017-7279
    40В плане

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    unitrends · enterprise backup12 апр. 2017 г.

  • CVE-2018-20512
    40В плане

    EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cdatatec · epon cpe-wifi devices firmware3 янв. 2019 г.

  • CVE-2018-5455
    39Наблюдать

    A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    moxa · oncell g3110-hspa firmware5 мар. 2018 г.

  • CVE-2018-5190
    39Наблюдать

    PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    picturespro · picturespro17 апр. 2018 г.

  • CVE-2022-38297
    39Наблюдать

    UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ucms project · ucms12 сент. 2022 г.

  • CVE-2014-125112
    39Наблюдать

    Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    miyagawa · plack\25 мар. 2026 г.

  • CVE-2025-14440
    39Наблюдать

    JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    jayarsiech · jay login & register13 дек. 2025 г.

  • CVE-2024-28288
    39Наблюдать

    Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    ruijie · rg-nbr700gw firmware29 мар. 2024 г.

  • CVE-2023-41084
    39Наблюдать

    Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    socomec · modulys gp firmware18 сент. 2023 г.

  • CVE-2025-2395
    39Наблюдать

    e-Excellence U-Office Force - Improper Authentication

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    edetw · u-office force17 мар. 2025 г.

  • CVE-2024-0947
    39Наблюдать

    Cookies Manipulation in Talya Informatics' Elektraweb

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    talya informatics · elektraweb27 июн. 2024 г.

  • CVE-2022-22785
    37Наблюдать

    Improperly constrained session cookies in Zoom Client for Meetings

    КритическаяCVSS 9,1Эксплойта нетEPSS 3 %

    zoom · meetings18 мая 2022 г.

  • CVE-2026-85181
    37Наблюдать

    CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    dianping · cat3 сент. 2026 г.

  • CVE-2017-6896
    36Наблюдать

    Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a

    ВысокаяCVSS 8,8Proof of conceptEPSS 4 %

    digisol · dg-hr1400 router firmware14 мар. 2017 г.

  • CVE-2012-5631
    36Наблюдать

    ipa 3.0 does not properly check server identity before sending credential containing cookies

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    freeipa · freeipa25 нояб. 2019 г.

  • CVE-2026-76186
    36Наблюдать

    Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    apache · apache-airflow-providers-keycloak16 сент. 2026 г.

  • CVE-2025-64447
    35Наблюдать

    A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu

    ВысокаяCVSS 8,1Эксплойта нетEPSS 8 %

    fortinet · fortiweb9 дек. 2025 г.

  • CVE-2023-32725
    35Наблюдать

    Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    zabbix · zabbix server18 дек. 2023 г.

  • CVE-2024-9970
    35Наблюдать

    NewType FlowMaster BPM Plus - Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    newtype · flowmaster bpm plus15 окт. 2024 г.

  • CVE-2026-5130
    35Наблюдать

    Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    jhimross · debugger & troubleshooter30 мар. 2026 г.

Все классы уязвимостей