CWE-1004 · 33 kayıt
Sensitive Cookie Without 'HttpOnly' Flag
Bu sınıftaki CVE’ler
33 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2025-26844İstismar yok | An issue was discovered in Znuny through 7.1.3.znuny · znuny · CWE-1004 | Kritik9,8 | — | %0,4 | 8 May 2025 |
36İzleyin | CVE-2021-42115İstismar yok | Missing HTTPOnly flag on sensitive cookie in TopEasebusinessdnasolutions · topease · CWE-1004 | Kritik9,1 | — | %1,3 | 30 Kas 2021 |
36İzleyin | CVE-2025-47289İstismar yok | Stored XSS in CE Phoenix Cart Testimonials Allows Account Takeover if Missing HttpOnly Flagphoenixcart · ce phoenix cart · CWE-1004 | Kritik9,0 | — | %0,2 | 2 Haz 2025 |
35İzleyin | CVE-2026-22081İstismar yok | Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routerstenda · 300mbps wireless router f3 and n300 easy setup router · CWE-1004 | Yüksek8,8 | — | %0,4 | 9 Oca 2026 |
32İzleyin | CVE-2026-42239İstismar yok | Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeoverbudibase · budibase · CWE-1004 | Yüksek8,1 | — | %0,4 | 7 May 2026 |
32İzleyin | GHSA-f777-f784-36gmİstismar yok | TYPO3 Security Misconfiguration in Install Tool CookiePackagist · typo3/cms · CWE-1004 | Yüksek8,1 | — | — | 7 Haz 2024 |
31İzleyin | CVE-2025-27223Kavram kanıtı | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPorrocketsoftware · trufusion enterprise · CWE-1004 | Yüksek7,5 | — | %2,2 | 27 Eki 2025 |
30İzleyin | CVE-2021-3706İstismar yok | Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminltepi-hole · web interface · CWE-1004 | Yüksek7,5 | — | %1,1 | 15 Eyl 2021 |
30İzleyin | CVE-2022-33167İstismar yok | IBM Security Directory Integrator information disclosureibm · security directory integrator · CWE-1004 | Yüksek7,5 | — | %0,4 | 30 Tem 2024 |
30İzleyin | CVE-2022-43845İstismar yok | IBM Aspera Console information disclosureibm · aspera console · CWE-1004 | Yüksek7,5 | — | %0,4 | 24 Eyl 2024 |
30İzleyin | GHSA-ppvg-hw62-6ph9İstismar yok | TYPO3 Security Misconfiguration in Install Tool CookiePackagist · typo3/cms-core · CWE-1004 | Yüksek7,5 | — | — | 30 May 2024 |
29İzleyin | CVE-2026-53660İstismar yok | OpenAM Insecure SSO Cookie Initializationopenidentityplatform · openam · CWE-1004 | Yüksek7,4 | — | %0,4 | 15 Eyl 2026 |
27İzleyin | CVE-2024-41685İstismar yok | Cookie Without HTTPOnly Flag Set Vulnerabilitysyrotech · sy-gpon-1110-wdont firmware · CWE-1004 | Orta6,9 | — | %0,5 | 26 Tem 2024 |
26İzleyin | CVE-2019-8283İstismar yok | Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag.gemalto · sentinel ldk · CWE-1004 | Orta6,5 | — | %1,2 | 7 Haz 2019 |
26İzleyin | CVE-2021-39210İstismar yok | Autologin cookie accessible by scriptsglpi-project · glpi · CWE-1004 | Orta6,5 | — | %1,0 | 15 Eyl 2021 |
26İzleyin | CVE-2025-27453İstismar yok | The HttpOnly flag is set to false on the PHPSESSION cookie.endress · meac300-fnade4 firmware · CWE-1004 | Orta6,5 | — | %0,4 | 3 Tem 2025 |
26İzleyin | CVE-2026-0696İstismar yok | Session Cookies Missing HttpOnly Attributeconnectwise · professional service automation · CWE-1004 | Orta6,5 | — | %0,4 | 16 Oca 2026 |
24İzleyin | CVE-2020-27658İstismar yok | Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makesynology · router manager · CWE-1004 | Orta6,1 | — | %1,3 | 29 Eki 2020 |
24İzleyin | CVE-2022-25172İstismar yok | An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4.inhandnetworks · ir302 firmware · CWE-1004 | Orta6,1 | — | %1,0 | 12 May 2022 |
24İzleyin | CVE-2022-21939İstismar yok | Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)johnsoncontrols · metasys system configuration tool · CWE-1004 | Orta6,1 | — | %0,5 | 9 Şub 2023 |
24İzleyin | CVE-2024-6739İstismar yok | Openfind MailGates and MailAudit - Sensitive Cookie Without 'HttpOnly' Flagopenfind · mailaudit · CWE-1004 | Orta6,1 | — | %0,4 | 15 Tem 2024 |
24İzleyin | CVE-2025-49189İstismar yok | Cookie missing HttpOnly flagsick · media server · CWE-1004 | Orta6,1 | — | %0,3 | 12 Haz 2025 |
24İzleyin | CVE-2023-2876İstismar yok | Session cookie exposure for client side scriptabb · rex640 pcl1 firmware · CWE-1004 | Orta6,1 | — | %0,3 | 13 Haz 2023 |
23İzleyin | CVE-2025-24318İstismar yok | Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Sensitive Cookie Without 'HttpOnly' Flagdario health · dario application database and internet-based server infrastructure · CWE-1004 | Orta5,9 | — | %0,4 | 28 Şub 2025 |
21İzleyin | CVE-2020-6267İstismar yok | Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only sap · disclosure management · CWE-1004 | Orta5,4 | — | %0,8 | 14 Tem 2020 |
- CVE-2025-2684439İzleyin
An issue was discovered in Znuny through 7.1.3.
KritikCVSS 9,8İstismar yokEPSS %0znuny · znuny8 May 2025
- CVE-2021-4211536İzleyin
Missing HTTPOnly flag on sensitive cookie in TopEase
KritikCVSS 9,1İstismar yokEPSS %1businessdnasolutions · topease30 Kas 2021
- CVE-2025-4728936İzleyin
Stored XSS in CE Phoenix Cart Testimonials Allows Account Takeover if Missing HttpOnly Flag
KritikCVSS 9,0İstismar yokEPSS %0phoenixcart · ce phoenix cart2 Haz 2025
- CVE-2026-2208135İzleyin
Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routers
YüksekCVSS 8,8İstismar yokEPSS %0tenda · 300mbps wireless router f3 and n300 easy setup router9 Oca 2026
- CVE-2026-4223932İzleyin
Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover
YüksekCVSS 8,1İstismar yokEPSS %0budibase · budibase7 May 2026
- GHSA-f777-f784-36gm32İzleyin
TYPO3 Security Misconfiguration in Install Tool Cookie
YüksekCVSS 8,1İstismar yokPackagist · typo3/cms7 Haz 2024
- CVE-2025-2722331İzleyin
TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPor
YüksekCVSS 7,5Kavram kanıtıEPSS %2rocketsoftware · trufusion enterprise27 Eki 2025
- CVE-2021-370630İzleyin
Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte
YüksekCVSS 7,5İstismar yokEPSS %1pi-hole · web interface15 Eyl 2021
- CVE-2022-3316730İzleyin
IBM Security Directory Integrator information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · security directory integrator30 Tem 2024
- CVE-2022-4384530İzleyin
IBM Aspera Console information disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · aspera console24 Eyl 2024
- GHSA-ppvg-hw62-6ph930İzleyin
TYPO3 Security Misconfiguration in Install Tool Cookie
YüksekCVSS 7,5İstismar yokPackagist · typo3/cms-core30 May 2024
- CVE-2026-5366029İzleyin
OpenAM Insecure SSO Cookie Initialization
YüksekCVSS 7,4İstismar yokEPSS %0openidentityplatform · openam15 Eyl 2026
- CVE-2024-4168527İzleyin
Cookie Without HTTPOnly Flag Set Vulnerability
OrtaCVSS 6,9İstismar yokEPSS %0syrotech · sy-gpon-1110-wdont firmware26 Tem 2024
- CVE-2019-828326İzleyin
Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag.
OrtaCVSS 6,5İstismar yokEPSS %1gemalto · sentinel ldk7 Haz 2019
- CVE-2021-3921026İzleyin
Autologin cookie accessible by scripts
OrtaCVSS 6,5İstismar yokEPSS %1glpi-project · glpi15 Eyl 2021
- CVE-2025-2745326İzleyin
The HttpOnly flag is set to false on the PHPSESSION cookie.
OrtaCVSS 6,5İstismar yokEPSS %0endress · meac300-fnade4 firmware3 Tem 2025
- CVE-2026-069626İzleyin
Session Cookies Missing HttpOnly Attribute
OrtaCVSS 6,5İstismar yokEPSS %0connectwise · professional service automation16 Oca 2026
- CVE-2020-2765824İzleyin
Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which make
OrtaCVSS 6,1İstismar yokEPSS %1synology · router manager29 Eki 2020
- CVE-2022-2517224İzleyin
An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4.
OrtaCVSS 6,1İstismar yokEPSS %1inhandnetworks · ir302 firmware12 May 2022
- CVE-2022-2193924İzleyin
Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)
OrtaCVSS 6,1İstismar yokEPSS %1johnsoncontrols · metasys system configuration tool9 Şub 2023
- CVE-2024-673924İzleyin
Openfind MailGates and MailAudit - Sensitive Cookie Without 'HttpOnly' Flag
OrtaCVSS 6,1İstismar yokEPSS %0openfind · mailaudit15 Tem 2024
- CVE-2025-4918924İzleyin
Cookie missing HttpOnly flag
OrtaCVSS 6,1İstismar yokEPSS %0sick · media server12 Haz 2025
- CVE-2023-287624İzleyin
Session cookie exposure for client side script
OrtaCVSS 6,1İstismar yokEPSS %0abb · rex640 pcl1 firmware13 Haz 2023
- CVE-2025-2431823İzleyin
Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Sensitive Cookie Without 'HttpOnly' Flag
OrtaCVSS 5,9İstismar yokEPSS %0dario health · dario application database and internet-based server infrastructure28 Şub 2025
- CVE-2020-626721İzleyin
Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only
OrtaCVSS 5,4İstismar yokEPSS %1sap · disclosure management14 Tem 2020