İçeriğe atla
Noroxi

CWE-565 · 61 kayıt

Reliance on Cookies without Validation and Integrity Checking

Bu sınıftaki CVE’ler

61 kayıt

  • PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities

    YüksekCVSS 7,8KEVSilahlaştırılmışEPSS %96

    paloaltonetworks · pan-os13 May 2026

  • CVE-2023-35885
    61Bu hafta

    CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.

    KritikCVSS 9,8Kavram kanıtıEPSS %75

    mgt-commerce · cloudpanel20 Haz 2023

  • CVE-2008-5784
    41Planlayın

    V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin

    KritikCVSS 9,8Kavram kanıtıEPSS %7

    v3chat · v3 chat profiles dating script31 Ara 2008

  • CVE-2025-65212
    41Planlayın

    An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1.

    KritikCVSS 9,8İstismar yokEPSS %5

    njhyst · hy511 firmware6 Oca 2026

  • CVE-2019-7266
    40Planlayın

    Linear eMerge 50P/5000P devices allow Authentication Bypass.

    KritikCVSS 9,8İstismar yokEPSS %5

    nortekcontrol · linear emerge 50p firmware2 Tem 2019

  • CVE-2017-7279
    40Planlayın

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" coo

    KritikCVSS 9,8İstismar yokEPSS %4

    unitrends · enterprise backup12 Nis 2017

  • CVE-2018-20512
    40Planlayın

    EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

    KritikCVSS 9,8İstismar yokEPSS %2

    cdatatec · epon cpe-wifi devices firmware3 Oca 2019

  • CVE-2018-5455
    39İzleyin

    A Reliance on Cookies without Validation and Integrity Checking issue was discovered in Moxa OnCell G3100-HSPA Series version 1.4 Build 1606

    KritikCVSS 9,8İstismar yokEPSS %2

    moxa · oncell g3110-hspa firmware5 Mar 2018

  • CVE-2018-5190
    39İzleyin

    PicturesPro Photo Cart 6 and 7 before Security-Patch-2018-B allows remote attackers to access arbitrary customer accounts via a modified coo

    KritikCVSS 9,8İstismar yokEPSS %1

    picturespro · picturespro17 Nis 2018

  • CVE-2022-38297
    39İzleyin

    UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

    KritikCVSS 9,8İstismar yokEPSS %1

    ucms project · ucms12 Eyl 2022

  • CVE-2014-125112
    39İzleyin

    Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution

    KritikCVSS 9,8İstismar yokEPSS %1

    miyagawa · plack\25 Mar 2026

  • CVE-2025-14440
    39İzleyin

    JAY Login & Register <= 2.4.01 - Authentication Bypass via Cookie

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    jayarsiech · jay login & register13 Ara 2025

  • CVE-2024-28288
    39İzleyin

    Ruijie RG-NBR700GW 10.3(4b12) router lacks cookie verification when resetting the password, resulting in an administrator password reset vul

    KritikCVSS 9,8İstismar yokEPSS %1

    ruijie · rg-nbr700gw firmware29 Mar 2024

  • CVE-2023-41084
    39İzleyin

    Socomec MOD3GP-SY-120K Reliance on Cookies without Validation and Integrity Checking

    KritikCVSS 9,8İstismar yokEPSS %1

    socomec · modulys gp firmware18 Eyl 2023

  • CVE-2025-2395
    39İzleyin

    e-Excellence U-Office Force - Improper Authentication

    KritikCVSS 9,8İstismar yokEPSS %1

    edetw · u-office force17 Mar 2025

  • CVE-2024-0947
    39İzleyin

    Cookies Manipulation in Talya Informatics' Elektraweb

    KritikCVSS 9,8İstismar yokEPSS %0

    talya informatics · elektraweb27 Haz 2024

  • CVE-2022-22785
    37İzleyin

    Improperly constrained session cookies in Zoom Client for Meetings

    KritikCVSS 9,1İstismar yokEPSS %3

    zoom · meetings18 May 2022

  • CVE-2026-85181
    37İzleyin

    CAT through 3.1.0 Session Cookie Forgery via Unkeyed hashCode Checksum

    KritikCVSS 9,3İstismar yokEPSS %1

    dianping · cat3 Eyl 2026

  • CVE-2017-6896
    36İzleyin

    Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to a

    YüksekCVSS 8,8Kavram kanıtıEPSS %4

    digisol · dg-hr1400 router firmware14 Mar 2017

  • CVE-2012-5631
    36İzleyin

    ipa 3.0 does not properly check server identity before sending credential containing cookies

    YüksekCVSS 8,8İstismar yokEPSS %2

    freeipa · freeipa25 Kas 2019

  • CVE-2026-76186
    36İzleyin

    Apache Airflow Keycloak provider: Keycloak token cookies not bound to Airflow session identity

    KritikCVSS 9,1İstismar yokEPSS %1

    apache · apache-airflow-providers-keycloak16 Eyl 2026

  • CVE-2025-64447
    35İzleyin

    A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 throu

    YüksekCVSS 8,1İstismar yokEPSS %8

    fortinet · fortiweb9 Ara 2025

  • CVE-2023-32725
    35İzleyin

    Leak of zbx_session cookie when using a scheduled report that includes a dashboard with a URL widget.

    YüksekCVSS 8,8İstismar yokEPSS %1

    zabbix · zabbix server18 Ara 2023

  • CVE-2024-9970
    35İzleyin

    NewType FlowMaster BPM Plus - Privilege Escalation

    YüksekCVSS 8,8İstismar yokEPSS %1

    newtype · flowmaster bpm plus15 Eki 2024

  • CVE-2026-5130
    35İzleyin

    Debugger & Troubleshooter <= 1.3.2 - Unauthenticated Privilege Escalation to Administrator via Cookie Manipulation

    YüksekCVSS 8,8İstismar yokEPSS %1

    jhimross · debugger & troubleshooter30 Mar 2026

Tüm zafiyet sınıfları