İçeriğe atla
Noroxi

CWE-1259 · 15 kayıt

Improper Restriction of Security Token Assignment

Bu sınıftaki CVE’ler

15 kayıt

  • CVE-2024-36533
    39İzleyin

    Insecure permissions in volcano v1.8.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's

    KritikCVSS 9,8İstismar yokEPSS %0

    24 Tem 2024

  • CVE-2026-54593
    32İzleyin

    Pterodactyl's improper JWT scoping allows subuser to upload files when not explicitly granted `file.create` permissions

    YüksekCVSS 8,1İstismar yokEPSS %1

    pterodactyl · panel28 Tem 2026

  • CVE-2026-76413
    32İzleyin

    Cisco Secure Firewall Management Center Software Single Sign-On Token Forgery of Administrator Account Vulnerability

    YüksekCVSS 8,2İstismar yokEPSS %0

    cisco · cisco secure firewall management center (fmc)16 Eyl 2026

  • CVE-2024-29371
    30İzleyin

    In jose4j before 0.9.6, an attacker can cause a Denial-of-Service (DoS) condition by crafting a malicious JSON Web Encryption (JWE) token wi

    YüksekCVSS 7,5İstismar yokEPSS %0

    jose4j project · jose4j17 Ara 2025

  • CVE-2024-36111
    28İzleyin

    KubePi's JWT token validation has a defect

    OrtaCVSS 6,3İstismar yokEPSS %8

    1panel-dev · kubepi25 Tem 2024

  • CVE-2026-25700
    28İzleyin

    Apache Answer: AdminToken not invalidated after admin deactivation

    YüksekCVSS 7,2İstismar yokEPSS %1

    apache · answer10 Haz 2026

  • CVE-2025-51306
    26İzleyin

    In Gatling Enterprise versions below 1.25.0, a user logging-out can still use his session token to continue using the application without ex

    OrtaCVSS 6,5İstismar yokEPSS %0

    gatling · gatling6 Ağu 2025

  • CVE-2025-27955
    26İzleyin

    Clinical Collaboration Platform 12.2.1.5 has a weak logout system where the session token remains valid after logout and allows a remote att

    OrtaCVSS 6,5İstismar yokEPSS %0

    philips · clinical collaboration platform2 Haz 2025

  • CVE-2025-56207
    26İzleyin

    A security flaw in the '_transfer' function of a smart contract implementation for Money Making Opportunity (MMO), an Ethereum ERC721 Non-Fu

    OrtaCVSS 6,5İstismar yokEPSS %0

    30 Eyl 2025

  • CVE-2024-4598
    26İzleyin

    Information Disclosure in Multiple WSO2 Products Due to Improper Handling in Enrich Mediator

    OrtaCVSS 6,5İstismar yokEPSS %0

    wso2 · api manager23 Eyl 2025

  • CVE-2024-45448
    22İzleyin

    Page table protection configuration vulnerability in the trusted firmware module Impact: Successful exploitation of this vulnerability may a

    OrtaCVSS 5,5İstismar yokEPSS %0

    huawei · emui3 Eyl 2024

  • CVE-2025-50579
    21İzleyin

    A CORS misconfiguration in Nginx Proxy Manager v2.12.3 allows unauthorized domains to access sensitive data, particularly JWT tokens, due to

    OrtaCVSS 5,3İstismar yokEPSS %0

    jc21 · nginx proxy manager19 Ağu 2025

  • CVE-2025-56676
    21İzleyin

    TitanSystems Zender v3.9.7 contains an account takeover vulnerability in its password reset functionality.

    OrtaCVSS 5,4İstismar yokEPSS %0

    titansystems · zender30 Eyl 2025

  • CVE-2024-41948
    20İzleyin

    biscuit-java vulnerable to public key confusion in third party block

    OrtaCVSS 5,0İstismar yokEPSS %0

    biscuitsec · biscuit-java1 Ağu 2024

  • OpenBao's Token Store Allows Cross-Namespace Renewal, Revocation

    DüşükCVSS 2,0İstismar yokEPSS %0

    openbao · openbao20 Nis 2026

Tüm zafiyet sınıfları