Перейти к содержимому
Noroxi

CWE-602 · 161 записей

Client-Side Enforcement of Server-Side Security

CVE этого класса

161 записей

  • CVE-2026-64813
    40В плане

    In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    jetbrains · intellij idea23 июл. 2026 г.

  • CVE-2026-23478
    40В плане

    Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    cal · cal.com13 янв. 2026 г.

  • CVE-2026-42160
    40В плане

    Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    sovity · dataspace-portal8 мая 2026 г.

  • CVE-2025-51682
    39Наблюдать

    mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to adminis

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mjobtime · mjobtime1 дек. 2025 г.

  • CVE-2025-10640
    39Наблюдать

    Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    efficientlab · workexaminer professional21 окт. 2025 г.

  • CVE-2025-27681
    39Наблюдать

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    printerlogic · vasion print5 мар. 2025 г.

  • CVE-2024-12603
    39Наблюдать

    A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    tecno · com.transsion.applock12 дек. 2024 г.

  • CVE-2023-0750
    39Наблюдать

    Yellowbrik PEC-1864 authentication bypass

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    lynx-technik · yellobrik pec 1864 firmware6 апр. 2023 г.

  • CVE-2025-28168
    39Наблюдать

    The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload.

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    multiple file upload project · multiple file upload5 мая 2025 г.

  • CVE-2022-20658
    38Наблюдать

    Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    cisco · unified contact center express14 янв. 2022 г.

  • CVE-2025-32469
    37Наблюдать

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    siemens · ruggedcom rox mx500013 мая 2025 г.

  • CVE-2025-33024
    37Наблюдать

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    siemens · ruggedcom rox mx500013 мая 2025 г.

  • CVE-2025-33025
    37Наблюдать

    A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    siemens · ruggedcom rox mx500013 мая 2025 г.

  • CVE-2024-23666
    36Наблюдать

    A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    fortinet · fortianalyzer12 нояб. 2024 г.

  • CVE-2022-1525
    36Наблюдать

    Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    cognex · 3d-a1000 dimensioning system firmware6 сент. 2022 г.

  • CVE-2026-59504
    36Наблюдать

    Priority – CWE-602: Client-Side Enforcement of Server-Side Security

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    priority · portal generator addon to priority erp (developed by soft solutions)13 авг. 2026 г.

  • CVE-2026-25737
    36Наблюдать

    Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)

    КритическаяCVSS 9,0Эксплойта нетEPSS 0 %

    budibase · budibase9 мар. 2026 г.

  • CVE-2017-12161
    35Наблюдать

    It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset reque

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    keycloak · keycloak21 февр. 2018 г.

  • CVE-2024-9844
    35Наблюдать

    Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticat

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    ivanti · connect secure10 дек. 2024 г.

  • CVE-2024-31491
    35Наблюдать

    A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    fortinet · fortisandbox14 мая 2024 г.

  • CVE-2024-28029
    35Наблюдать

    Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    deltaww · diaenergie21 мар. 2024 г.

  • CVE-2026-14086
    35Наблюдать

    Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a cra

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    google · chrome30 июн. 2026 г.

  • CVE-2025-61197
    35Наблюдать

    An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    6 окт. 2025 г.

  • CVE-2025-33137
    35Наблюдать

    IBM Aspera Faspex data modification

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ibm · aspera faspex22 мая 2025 г.

  • CVE-2026-13903
    35Наблюдать

    Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalati

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    google · chrome30 июн. 2026 г.

Все классы уязвимостей