CWE-602 · 161 записей
Client-Side Enforcement of Server-Side Security
CVE этого класса
161 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2026-64813Эксплойта нет | In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development sessionjetbrains · intellij idea · CWE-602 | Критическая10,0 | — | 0,5 % | 23 июл. 2026 г. |
40В плане | CVE-2026-23478Эксплойта нет | Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callbackcal · cal.com · CWE-602 | Критическая10,0 | — | 0,5 % | 13 янв. 2026 г. |
40В плане | CVE-2026-42160Эксплойта нет | Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backendsovity · dataspace-portal · CWE-602 | Критическая10,0 | — | 0,4 % | 8 мая 2026 г. |
39Наблюдать | CVE-2025-51682Эксплойта нет | mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to adminismjobtime · mjobtime · CWE-602 | Критическая9,8 | — | 1,6 % | 1 дек. 2025 г. |
39Наблюдать | CVE-2025-10640Эксплойта нет | Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professionalefficientlab · workexaminer professional · CWE-602 | Критическая9,8 | — | 0,9 % | 21 окт. 2025 г. |
39Наблюдать | CVE-2025-27681Эксплойта нет | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-printerlogic · vasion print · CWE-602 | Критическая9,8 | — | 0,8 % | 5 мар. 2025 г. |
39Наблюдать | CVE-2024-12603Эксплойта нет | A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.tecno · com.transsion.applock · CWE-602 | Критическая9,8 | — | 0,6 % | 12 дек. 2024 г. |
39Наблюдать | CVE-2023-0750Эксплойта нет | Yellowbrik PEC-1864 authentication bypasslynx-technik · yellobrik pec 1864 firmware · CWE-602 | Критическая9,8 | — | 0,5 % | 6 апр. 2023 г. |
39Наблюдать | CVE-2025-28168Эксплойта нет | The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload.multiple file upload project · multiple file upload · CWE-602 | Критическая9,8 | — | 0,3 % | 5 мая 2025 г. |
38Наблюдать | CVE-2022-20658Эксплойта нет | Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerabilitycisco · unified contact center express · CWE-602 | Критическая9,6 | — | 1,4 % | 14 янв. 2022 г. |
37Наблюдать | CVE-2025-32469Эксплойта нет | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEsiemens · ruggedcom rox mx5000 · CWE-602 | Критическая9,4 | — | 1,2 % | 13 мая 2025 г. |
37Наблюдать | CVE-2025-33024Эксплойта нет | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEsiemens · ruggedcom rox mx5000 · CWE-602 | Критическая9,4 | — | 1,2 % | 13 мая 2025 г. |
37Наблюдать | CVE-2025-33025Эксплойта нет | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGEsiemens · ruggedcom rox mx5000 · CWE-602 | Критическая9,4 | — | 1,2 % | 13 мая 2025 г. |
36Наблюдать | CVE-2024-23666Proof of concept | A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0fortinet · fortianalyzer · CWE-602 | Высокая8,8 | — | 2,7 % | 12 нояб. 2024 г. |
36Наблюдать | CVE-2022-1525Эксплойта нет | Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Securitycognex · 3d-a1000 dimensioning system firmware · CWE-602 | Критическая9,1 | — | 0,8 % | 6 сент. 2022 г. |
36Наблюдать | CVE-2026-59504Эксплойта нет | Priority – CWE-602: Client-Side Enforcement of Server-Side Securitypriority · portal generator addon to priority erp (developed by soft solutions) · CWE-602 | Критическая9,1 | — | 0,4 % | 13 авг. 2026 г. |
36Наблюдать | CVE-2026-25737Эксплойта нет | Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)budibase · budibase · CWE-602 | Критическая9,0 | — | 0,4 % | 9 мар. 2026 г. |
35Наблюдать | CVE-2017-12161Эксплойта нет | It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset requekeycloak · keycloak · CWE-602 | Высокая8,8 | — | 1,3 % | 21 февр. 2018 г. |
35Наблюдать | CVE-2024-9844Эксплойта нет | Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticativanti · connect secure · CWE-602 | Высокая8,8 | — | 1,0 % | 10 дек. 2024 г. |
35Наблюдать | CVE-2024-31491Эксплойта нет | A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2fortinet · fortisandbox · CWE-602 | Высокая8,8 | — | 0,8 % | 14 мая 2024 г. |
35Наблюдать | CVE-2024-28029Эксплойта нет | Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergiedeltaww · diaenergie · CWE-602 | Высокая8,8 | — | 0,7 % | 21 мар. 2024 г. |
35Наблюдать | CVE-2026-14086Эксплойта нет | Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a cragoogle · chrome · CWE-602 | Высокая8,8 | — | 0,4 % | 30 июн. 2026 г. |
35Наблюдать | CVE-2025-61197Эксплойта нет | An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26 CWE-602 | Высокая8,9 | — | 0,3 % | 6 окт. 2025 г. |
35Наблюдать | CVE-2025-33137Эксплойта нет | IBM Aspera Faspex data modificationibm · aspera faspex · CWE-602 | Высокая8,8 | — | 0,3 % | 22 мая 2025 г. |
35Наблюдать | CVE-2026-13903Эксплойта нет | Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalatigoogle · chrome · CWE-602 | Высокая8,8 | — | 0,3 % | 30 июн. 2026 г. |
- CVE-2026-6481340В плане
In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %jetbrains · intellij idea23 июл. 2026 г.
- CVE-2026-2347840В плане
Cal.com has an Authentication Bypass via Unvalidated Email in Custom JWT Callback
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %cal · cal.com13 янв. 2026 г.
- CVE-2026-4216040В плане
Data Space Portal: Incorrect Authorization and Client-Side Enforcement of Server-Side Security in ghcr.io/sovity/ds-portal-ce-backend
КритическаяCVSS 10,0Эксплойта нетEPSS 0 %sovity · dataspace-portal8 мая 2026 г.
- CVE-2025-5168239Наблюдать
mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and gain access to adminis
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mjobtime · mjobtime1 дек. 2025 г.
- CVE-2025-1064039Наблюдать
Missing Server-Side Authentication Checks in EfficientLab WorkExaminer Professional
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %efficientlab · workexaminer professional21 окт. 2025 г.
- CVE-2025-2768139Наблюдать
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %printerlogic · vasion print5 мар. 2025 г.
- CVE-2024-1260339Наблюдать
A logic vulnerability in the the mobile application (com.transsion.applock) can lead to bypassing the application password.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %tecno · com.transsion.applock12 дек. 2024 г.
- CVE-2023-075039Наблюдать
Yellowbrik PEC-1864 authentication bypass
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %lynx-technik · yellobrik pec 1864 firmware6 апр. 2023 г.
- CVE-2025-2816839Наблюдать
The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload.
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %multiple file upload project · multiple file upload5 мая 2025 г.
- CVE-2022-2065838Наблюдать
Cisco Unified Contact Center Management Portal and Unified Contact Center Domain Manager Privilege Escalation Vulnerability
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %cisco · unified contact center express14 янв. 2022 г.
- CVE-2025-3246937Наблюдать
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %siemens · ruggedcom rox mx500013 мая 2025 г.
- CVE-2025-3302437Наблюдать
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %siemens · ruggedcom rox mx500013 мая 2025 г.
- CVE-2025-3302537Наблюдать
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versions < V2.16.5), RUGGE
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %siemens · ruggedcom rox mx500013 мая 2025 г.
- CVE-2024-2366636Наблюдать
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0
ВысокаяCVSS 8,8Proof of conceptEPSS 3 %fortinet · fortianalyzer12 нояб. 2024 г.
- CVE-2022-152536Наблюдать
Cognex 3D-A1000 Dimensioning System Client-Side Enforcement of Server-Side Security
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cognex · 3d-a1000 dimensioning system firmware6 сент. 2022 г.
- CVE-2026-5950436Наблюдать
Priority – CWE-602: Client-Side Enforcement of Server-Side Security
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %priority · portal generator addon to priority erp (developed by soft solutions)13 авг. 2026 г.
- CVE-2026-2573736Наблюдать
Budibase Arbitrary File Upload Leading to Multiple Critical Vulnerabilities (SSRF, Stored XSS)
КритическаяCVSS 9,0Эксплойта нетEPSS 0 %budibase · budibase9 мар. 2026 г.
- CVE-2017-1216135Наблюдать
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset reque
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %keycloak · keycloak21 февр. 2018 г.
- CVE-2024-984435Наблюдать
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticat
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ivanti · connect secure10 дек. 2024 г.
- CVE-2024-3149135Наблюдать
A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %fortinet · fortisandbox14 мая 2024 г.
- CVE-2024-2802935Наблюдать
Client-Side Enforcement of Server-Side Security in Delta Electronics DIAEnergie
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %deltaww · diaenergie21 мар. 2024 г.
- CVE-2026-1408635Наблюдать
Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a cra
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome30 июн. 2026 г.
- CVE-2025-6119735Наблюдать
An issue in Orban Optimod 5950, Optimod 5950HD, Optimod 5750, Optimod 5750HD, Optimod Trio Optimod version 1.0.0.33 - System version 2.5.26
ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %6 окт. 2025 г.
- CVE-2025-3313735Наблюдать
IBM Aspera Faspex data modification
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ibm · aspera faspex22 мая 2025 г.
- CVE-2026-1390335Наблюдать
Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalati
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %google · chrome30 июн. 2026 г.