İçeriğe atla
Noroxi

CWE-1004 · 33 kayıt

Sensitive Cookie Without 'HttpOnly' Flag

Bu sınıftaki CVE’ler

33 kayıt

  • CVE-2025-26844
    39İzleyin

    An issue was discovered in Znuny through 7.1.3.

    KritikCVSS 9,8İstismar yokEPSS %0

    znuny · znuny8 May 2025

  • CVE-2021-42115
    36İzleyin

    Missing HTTPOnly flag on sensitive cookie in TopEase

    KritikCVSS 9,1İstismar yokEPSS %1

    businessdnasolutions · topease30 Kas 2021

  • CVE-2025-47289
    36İzleyin

    Stored XSS in CE Phoenix Cart Testimonials Allows Account Takeover if Missing HttpOnly Flag

    KritikCVSS 9,0İstismar yokEPSS %0

    phoenixcart · ce phoenix cart2 Haz 2025

  • CVE-2026-22081
    35İzleyin

    Cookie without HTTPOnly Flag Vulnerability in Tenda Wireless Routers

    YüksekCVSS 8,8İstismar yokEPSS %0

    tenda · 300mbps wireless router f3 and n300 easy setup router9 Oca 2026

  • CVE-2026-42239
    32İzleyin

    Budibase auth session cookies are set with httpOnly:false — any XSS can lead to full account takeover

    YüksekCVSS 8,1İstismar yokEPSS %0

    budibase · budibase7 May 2026

  • TYPO3 Security Misconfiguration in Install Tool Cookie

    YüksekCVSS 8,1İstismar yok

    Packagist · typo3/cms7 Haz 2024

  • CVE-2025-27223
    31İzleyin

    TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPor

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    rocketsoftware · trufusion enterprise27 Eki 2025

  • CVE-2021-3706
    30İzleyin

    Sensitive Cookie Without 'HttpOnly' Flag in pi-hole/adminlte

    YüksekCVSS 7,5İstismar yokEPSS %1

    pi-hole · web interface15 Eyl 2021

  • CVE-2022-33167
    30İzleyin

    IBM Security Directory Integrator information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · security directory integrator30 Tem 2024

  • CVE-2022-43845
    30İzleyin

    IBM Aspera Console information disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · aspera console24 Eyl 2024

  • TYPO3 Security Misconfiguration in Install Tool Cookie

    YüksekCVSS 7,5İstismar yok

    Packagist · typo3/cms-core30 May 2024

  • CVE-2026-53660
    29İzleyin

    OpenAM Insecure SSO Cookie Initialization

    YüksekCVSS 7,4İstismar yokEPSS %0

    openidentityplatform · openam15 Eyl 2026

  • CVE-2024-41685
    27İzleyin

    Cookie Without HTTPOnly Flag Set Vulnerability

    OrtaCVSS 6,9İstismar yokEPSS %0

    syrotech · sy-gpon-1110-wdont firmware26 Tem 2024

  • CVE-2019-8283
    26İzleyin

    Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag.

    OrtaCVSS 6,5İstismar yokEPSS %1

    gemalto · sentinel ldk7 Haz 2019

  • CVE-2021-39210
    26İzleyin

    Autologin cookie accessible by scripts

    OrtaCVSS 6,5İstismar yokEPSS %1

    glpi-project · glpi15 Eyl 2021

  • CVE-2025-27453
    26İzleyin

    The HttpOnly flag is set to false on the PHPSESSION cookie.

    OrtaCVSS 6,5İstismar yokEPSS %0

    endress · meac300-fnade4 firmware3 Tem 2025

  • CVE-2026-0696
    26İzleyin

    Session Cookies Missing HttpOnly Attribute

    OrtaCVSS 6,5İstismar yokEPSS %0

    connectwise · professional service automation16 Oca 2026

  • CVE-2020-27658
    24İzleyin

    Synology Router Manager (SRM) before 1.2.4-8081 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which make

    OrtaCVSS 6,1İstismar yokEPSS %1

    synology · router manager29 Eki 2020

  • CVE-2022-25172
    24İzleyin

    An information disclosure vulnerability exists in the web interface session cookie functionality of InHand Networks InRouter302 V3.5.4.

    OrtaCVSS 6,1İstismar yokEPSS %1

    inhandnetworks · ir302 firmware12 May 2022

  • CVE-2022-21939
    24İzleyin

    Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)

    OrtaCVSS 6,1İstismar yokEPSS %1

    johnsoncontrols · metasys system configuration tool9 Şub 2023

  • CVE-2024-6739
    24İzleyin

    Openfind MailGates and MailAudit - Sensitive Cookie Without 'HttpOnly' Flag

    OrtaCVSS 6,1İstismar yokEPSS %0

    openfind · mailaudit15 Tem 2024

  • CVE-2025-49189
    24İzleyin

    Cookie missing HttpOnly flag

    OrtaCVSS 6,1İstismar yokEPSS %0

    sick · media server12 Haz 2025

  • CVE-2023-2876
    24İzleyin

    Session cookie exposure for client side script

    OrtaCVSS 6,1İstismar yokEPSS %0

    abb · rex640 pcl1 firmware13 Haz 2023

  • CVE-2025-24318
    23İzleyin

    Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Sensitive Cookie Without 'HttpOnly' Flag

    OrtaCVSS 5,9İstismar yokEPSS %0

    dario health · dario application database and internet-based server infrastructure28 Şub 2025

  • CVE-2020-6267
    21İzleyin

    Some sensitive cookies in SAP Disclosure Management, version 10.1, are missing HttpOnly flag, leading to sensitive cookie without Http Only

    OrtaCVSS 5,4İstismar yokEPSS %1

    sap · disclosure management14 Tem 2020

Tüm zafiyet sınıfları