CWE-1259 · 15 kayıt
Improper Restriction of Security Token Assignment
Bu sınıftaki CVE’ler
15 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-36533İstismar yok | Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's CWE-1259 | Kritik9,8 | — | %0,5 | 24 Tem 2024 |
32İzleyin | CVE-2026-54593İstismar yok | Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissionspterodactyl · panel · CWE-1259 | Yüksek8,1 | — | %0,7 | 28 Tem 2026 |
32İzleyin | CVE-2026-76413İstismar yok | Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerabilitycisco · cisco secure firewall management center (fmc) · CWE-1259 | Yüksek8,2 | — | %0,5 | 16 Eyl 2026 |
30İzleyin | CVE-2024-29371İstismar yok | In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token wijose4j project · jose4j · CWE-1259 | Yüksek7,5 | — | %0,3 | 17 Ara 2025 |
28İzleyin | CVE-2024-36111İstismar yok | KubePi's JWT token validation has a defect1panel-dev · kubepi · CWE-1259 | Orta6,3 | — | %8,4 | 25 Tem 2024 |
28İzleyin | CVE-2026-25700İstismar yok | Apache Answer: AdminToken not invalidated after admin deactivationapache · answer · CWE-1259 | Yüksek7,2 | — | %0,7 | 10 Haz 2026 |
26İzleyin | CVE-2025-51306İstismar yok | In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without exgatling · gatling · CWE-1259 | Orta6,5 | — | %0,4 | 6 Ağu 2025 |
26İzleyin | CVE-2025-27955İstismar yok | Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote attphilips · clinical collaboration platform · CWE-1259 | Orta6,5 | — | %0,3 | 2 Haz 2025 |
26İzleyin | CVE-2025-56207İstismar yok | A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-FuCWE-1259 | Orta6,5 | — | %0,3 | 30 Eyl 2025 |
26İzleyin | CVE-2024-4598İstismar yok | Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediatorwso2 · api manager · CWE-1259 | Orta6,5 | — | %0,3 | 23 Eyl 2025 |
22İzleyin | CVE-2024-45448İstismar yok | Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may ahuawei · emui · CWE-1259 | Orta5,5 | — | %0,1 | 3 Eyl 2024 |
21İzleyin | CVE-2025-50579İstismar yok | A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due tojc21 · nginx proxy manager · CWE-1259 | Orta5,3 | — | %0,4 | 19 Ağu 2025 |
21İzleyin | CVE-2025-56676İstismar yok | TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality.titansystems · zender · CWE-1259 | Orta5,4 | — | %0,3 | 30 Eyl 2025 |
20İzleyin | CVE-2024-41948İstismar yok | biscuit-java vulnerable to public key confusion in third party blockbiscuitsec · biscuit-java · CWE-1259 | Orta5,0 | — | %0,3 | 1 Ağu 2024 |
8İzleyin | CVE-2026-40264İstismar yok | OpenBao's Token Store Allows Cross-Namespace Renewal, Revocationopenbao · openbao · CWE-1259 | Düşük2,0 | — | %0,4 | 20 Nis 2026 |
- CVE-2024-3653339İzleyin
Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's
KritikCVSS 9,8İstismar yokEPSS %024 Tem 2024
- CVE-2026-5459332İzleyin
Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions
YüksekCVSS 8,1İstismar yokEPSS %1pterodactyl · panel28 Tem 2026
- CVE-2026-7641332İzleyin
Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %0cisco · cisco secure firewall management center (fmc)16 Eyl 2026
- CVE-2024-2937130İzleyin
In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token wi
YüksekCVSS 7,5İstismar yokEPSS %0jose4j project · jose4j17 Ara 2025
- CVE-2024-3611128İzleyin
KubePi's JWT token validation has a defect
OrtaCVSS 6,3İstismar yokEPSS %81panel-dev · kubepi25 Tem 2024
- CVE-2026-2570028İzleyin
Apache Answer: AdminToken not invalidated after admin deactivation
YüksekCVSS 7,2İstismar yokEPSS %1apache · answer10 Haz 2026
- CVE-2025-5130626İzleyin
In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without ex
OrtaCVSS 6,5İstismar yokEPSS %0gatling · gatling6 Ağu 2025
- CVE-2025-2795526İzleyin
Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote att
OrtaCVSS 6,5İstismar yokEPSS %0philips · clinical collaboration platform2 Haz 2025
- CVE-2025-5620726İzleyin
A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-Fu
OrtaCVSS 6,5İstismar yokEPSS %030 Eyl 2025
- CVE-2024-459826İzleyin
Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator
OrtaCVSS 6,5İstismar yokEPSS %0wso2 · api manager23 Eyl 2025
- CVE-2024-4544822İzleyin
Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may a
OrtaCVSS 5,5İstismar yokEPSS %0huawei · emui3 Eyl 2024
- CVE-2025-5057921İzleyin
A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to
OrtaCVSS 5,3İstismar yokEPSS %0jc21 · nginx proxy manager19 Ağu 2025
- CVE-2025-5667621İzleyin
TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality.
OrtaCVSS 5,4İstismar yokEPSS %0titansystems · zender30 Eyl 2025
- CVE-2024-4194820İzleyin
biscuit-java vulnerable to public key confusion in third party block
OrtaCVSS 5,0İstismar yokEPSS %0biscuitsec · biscuit-java1 Ağu 2024
- CVE-2026-402648İzleyin
OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation
DüşükCVSS 2,0İstismar yokEPSS %0openbao · openbao20 Nis 2026