CWE-565

Reliance on Cookies without Validation and Integrity Checking

Parent: CWE-642 - External Control of Critical State Data

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

68 vulnerabilities with CWE-565
CVE-2022-50926 CRITICAL
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
CVSS 9.8
CVE-2025-65212 CRITICAL
NJHYST HY511 POE <2.1 - Auth Bypass
CVSS 9.8
CVE-2025-14440 CRITICAL
JAY Login & Register <2.4.01 - Auth Bypass
CVSS 9.8
CVE-2021-47706
COMMAX Biometric Access Control System 1.0.0 - Auth Bypass
CVE-2025-64447 HIGH
Fortinet FortiWeb <8.0.1 - CSRF
CVSS 8.1
CVE-2025-48980 MEDIUM
Brave Browser Desktop <1.83.10 - Info Disclosure
CVSS 6.5
CVE-2025-59247 HIGH
Microsoft Azure Playfab - Improper Privilege Management
CVSS 8.8
CVE-2025-31120 MEDIUM
NamelessMC <2.1.4 - Info Disclosure
CVSS 5.3
CVE-2024-55211 HIGH
Think Router Tk-Rt-Wr135G V3.0.2-X000 - Auth Bypass
CVSS 8.4
CVE-2025-2395 CRITICAL
U-Office Force - Auth Bypass
CVSS 9.8
CVE-2024-9970 HIGH
NewType FlowMaster BPM Plus - Privilege Escalation
CVSS 8.8
CVE-2024-9820 MEDIUM
Dueclic WP 2fa With Telegram < 3.1 - Authentication Bypass
CVSS 6.5
CVE-2024-21583 MEDIUM
github.com/gitpod-io/gitpod - Info Disclosure
CVSS 4.1
CVE-2024-39734 MEDIUM
IBM Datacap Navigator <9.1.10 - Open Redirect
CVSS 4.3
CVE-2024-0947 CRITICAL
Elektraweb <v17.0.68 - Session Credential Falsification
CVSS 9.8
CVE-2021-20450 MEDIUM
IBM Cognos Controller <11.0.0 - Open Redirect
CVSS 4.3
CVE-2024-22186 HIGH
Application - Privilege Escalation
CVSS 8.8
CVE-2024-21872 HIGH
Device - Auth Bypass
CVSS 7.5
CVE-2024-28288 CRITICAL
Ruijie RG-NBR700GW <10.3(4b12) - Auth Bypass
CVSS 9.8
CVE-2024-28233 HIGH
Jupyterhub < 4.1.0 - CSRF
CVSS 8.1
CVE-2024-1551 MEDIUM
Firefox <123, Firefox ESR <115.8, Thunderbird <115.8 - XSS
CVSS 6.1
CVE-2023-32725 CRITICAL
URL Widget - Auth Bypass
CVSS 9.6
CVE-2023-45141 HIGH
Fiber < 2.50.0 - CSRF
CVSS 8.6
CVE-2023-45128 CRITICAL
Fiber < 2.50.0 - CSRF
CVSS 10.0
CVE-2023-41084 CRITICAL
Web App <version> - Info Disclosure
CVSS 10.0
Details
Vulnerabilities 68