CWE-565 · 61 записей
Reliance on Cookies without Validation and Integrity Checking
CVE этого класса
61 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
90Срочно | CVE-2026-0257Готовый эксплойт | PAN-OS: GlobalProtect Authentication Bypass Vulnerabilitiespaloaltonetworks · pan-os · CWE-565 | Высокая7,8 | KEV | 96,4 % | 13 мая 2026 г. |
61На этой неделе | CVE-2023-35885Proof of concept | CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.mgt-commerce · cloudpanel · CWE-565 | Критическая9,8 | — | 74,9 % | 20 июн. 2023 г. |
41В плане | CVE-2008-5784Proof of concept | V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin v3chat · v3 chat profiles dating script · CWE-565 | Критическая9,8 | — | 7,1 % | 31 дек. 2008 г. |
41В плане | CVE-2025-65212Эксплойта нет | An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.njhyst · hy511 firmware · CWE-565 | Критическая9,8 | — | 5,2 % | 6 янв. 2026 г. |
40В плане | CVE-2019-7266Эксплойта нет | Linear eMerge 50P/5000P devices allow Authentication Bypass.nortekcontrol · linear emerge 50p firmware · CWE-565 | Критическая9,8 | — | 4,6 % | 2 июл. 2019 г. |
40В плане | CVE-2017-7279Эксплойта нет | An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coounitrends · enterprise backup · CWE-565 | Критическая9,8 | — | 4,4 % | 12 апр. 2017 г. |
40В плане | CVE-2018-20512Эксплойта нет | EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.cdatatec · epon cpe-wifi devices firmware · CWE-565 | Критическая9,8 | — | 1,8 % | 3 янв. 2019 г. |
39Наблюдать | CVE-2018-5455Эксплойта нет | A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606moxa · oncell g3110-hspa firmware · CWE-565 | Критическая9,8 | — | 1,6 % | 5 мар. 2018 г. |
39Наблюдать | CVE-2018-5190Эксплойта нет | PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coopicturespro · picturespro · CWE-565 | Критическая9,8 | — | 1,4 % | 17 апр. 2018 г. |
39Наблюдать | CVE-2022-38297Эксплойта нет | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.ucms project · ucms · CWE-565 | Критическая9,8 | — | 1,3 % | 12 сент. 2022 г. |
39Наблюдать | CVE-2014-125112Эксплойта нет | Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code executionmiyagawa · plack\ · CWE-565 | Критическая9,8 | — | 0,8 % | 25 мар. 2026 г. |
39Наблюдать | CVE-2025-14440Proof of concept | JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookiejayarsiech · jay login & register · CWE-565 | Критическая9,8 | — | 0,8 % | 13 дек. 2025 г. |
39Наблюдать | CVE-2024-28288Эксплойта нет | Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vulruijie · rg-nbr700gw firmware · CWE-565 | Критическая9,8 | — | 0,7 % | 29 мар. 2024 г. |
39Наблюдать | CVE-2023-41084Эксплойта нет | Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checkingsocomec · modulys gp firmware · CWE-565 | Критическая9,8 | — | 0,7 % | 18 сент. 2023 г. |
39Наблюдать | CVE-2025-2395Эксплойта нет | e-Excellence U-Office Force - Improper Authenticationedetw · u-office force · CWE-565 | Критическая9,8 | — | 0,6 % | 17 мар. 2025 г. |
39Наблюдать | CVE-2024-0947Эксплойта нет | Cookies Manipulation in Talya Informatics' Elektrawebtalya informatics · elektraweb · CWE-565 | Критическая9,8 | — | 0,5 % | 27 июн. 2024 г. |
37Наблюдать | CVE-2022-22785Эксплойта нет | Improperly constrained session cookies in Zoom Client for Meetingszoom · meetings · CWE-565 | Критическая9,1 | — | 3,5 % | 18 мая 2022 г. |
37Наблюдать | CVE-2026-85181Эксплойта нет | CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksumdianping · cat · CWE-565 | Критическая9,3 | — | 0,7 % | 3 сент. 2026 г. |
36Наблюдать | CVE-2017-6896Proof of concept | Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to adigisol · dg-hr1400 router firmware · CWE-565 | Высокая8,8 | — | 3,7 % | 14 мар. 2017 г. |
36Наблюдать | CVE-2012-5631Эксплойта нет | ipa 3.0 does not properly check server identity before sending credential containing cookiesfreeipa · freeipa · CWE-565 | Высокая8,8 | — | 1,8 % | 25 нояб. 2019 г. |
36Наблюдать | CVE-2026-76186Эксплойта нет | Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identityapache · apache-airflow-providers-keycloak · CWE-565 | Критическая9,1 | — | 0,8 % | 16 сент. 2026 г. |
35Наблюдать | CVE-2025-64447Эксплойта нет | A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throufortinet · fortiweb · CWE-565 | Высокая8,1 | — | 8,4 % | 9 дек. 2025 г. |
35Наблюдать | CVE-2023-32725Эксплойта нет | Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.zabbix · zabbix server · CWE-565 | Высокая8,8 | — | 0,8 % | 18 дек. 2023 г. |
35Наблюдать | CVE-2024-9970Эксплойта нет | NewType FlowMaster BPM Plus - Privilege Escalationnewtype · flowmaster bpm plus · CWE-565 | Высокая8,8 | — | 0,6 % | 15 окт. 2024 г. |
35Наблюдать | CVE-2026-5130Эксплойта нет | Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulationjhimross · debugger & troubleshooter · CWE-565 | Высокая8,8 | — | 0,6 % | 30 мар. 2026 г. |
- CVE-2026-025790Срочно
PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 96 %paloaltonetworks · pan-os13 мая 2026 г.
- CVE-2023-3588561На этой неделе
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
КритическаяCVSS 9,8Proof of conceptEPSS 75 %mgt-commerce · cloudpanel20 июн. 2023 г.
- CVE-2008-578441В плане
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin
КритическаяCVSS 9,8Proof of conceptEPSS 7 %v3chat · v3 chat profiles dating script31 дек. 2008 г.
- CVE-2025-6521241В плане
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %njhyst · hy511 firmware6 янв. 2026 г.
- CVE-2019-726640В плане
Linear eMerge 50P/5000P devices allow Authentication Bypass.
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %nortekcontrol · linear emerge 50p firmware2 июл. 2019 г.
- CVE-2017-727940В плане
An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %unitrends · enterprise backup12 апр. 2017 г.
- CVE-2018-2051240В плане
EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cdatatec · epon cpe-wifi devices firmware3 янв. 2019 г.
- CVE-2018-545539Наблюдать
A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %moxa · oncell g3110-hspa firmware5 мар. 2018 г.
- CVE-2018-519039Наблюдать
PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %picturespro · picturespro17 апр. 2018 г.
- CVE-2022-3829739Наблюдать
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ucms project · ucms12 сент. 2022 г.
- CVE-2014-12511239Наблюдать
Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %miyagawa · plack\25 мар. 2026 г.
- CVE-2025-1444039Наблюдать
JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie
КритическаяCVSS 9,8Proof of conceptEPSS 1 %jayarsiech · jay login & register13 дек. 2025 г.
- CVE-2024-2828839Наблюдать
Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %ruijie · rg-nbr700gw firmware29 мар. 2024 г.
- CVE-2023-4108439Наблюдать
Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %socomec · modulys gp firmware18 сент. 2023 г.
- CVE-2025-239539Наблюдать
e-Excellence U-Office Force - Improper Authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %edetw · u-office force17 мар. 2025 г.
- CVE-2024-094739Наблюдать
Cookies Manipulation in Talya Informatics' Elektraweb
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %talya informatics · elektraweb27 июн. 2024 г.
- CVE-2022-2278537Наблюдать
Improperly constrained session cookies in Zoom Client for Meetings
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %zoom · meetings18 мая 2022 г.
- CVE-2026-8518137Наблюдать
CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %dianping · cat3 сент. 2026 г.
- CVE-2017-689636Наблюдать
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %digisol · dg-hr1400 router firmware14 мар. 2017 г.
- CVE-2012-563136Наблюдать
ipa 3.0 does not properly check server identity before sending credential containing cookies
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %freeipa · freeipa25 нояб. 2019 г.
- CVE-2026-7618636Наблюдать
Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %apache · apache-airflow-providers-keycloak16 сент. 2026 г.
- CVE-2025-6444735Наблюдать
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu
ВысокаяCVSS 8,1Эксплойта нетEPSS 8 %fortinet · fortiweb9 дек. 2025 г.
- CVE-2023-3272535Наблюдать
Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %zabbix · zabbix server18 дек. 2023 г.
- CVE-2024-997035Наблюдать
NewType FlowMaster BPM Plus - Privilege Escalation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %newtype · flowmaster bpm plus15 окт. 2024 г.
- CVE-2026-513035Наблюдать
Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %jhimross · debugger & troubleshooter30 мар. 2026 г.