CWE-565
Reliance on Cookies without Validation and Integrity Checking
The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.
74 vulnerabilities with CWE-565
CVE-2023-45128
CRITICAL
Fiber < 2.50.0 - Cross-Site Request Forgery via Improper CSRF Token Validation
CVSS 10.0
CVE-2023-41084
CRITICAL
Web App <version> - Info Disclosure
CVSS 10.0
CVE-2023-3747
MEDIUM
Cloudflare WARP - Client-Side Enforcement Bypass via Local Date Manipulation
CVSS 5.5
CVE-2023-32612
HIGH
WL-WN531AX2 <2023526 - Command Injection
CVSS 7.2
CVE-2023-35885
CRITICAL
CloudPanel 2.0.0-2.3.0 - Unauthenticated Remote Code Execution via File Manager Cookie
CVSS 9.8
CVE-2023-3050
CRITICAL
TMT Lockcell Firmware < 15.0 - Authentication Bypass via Unvalidated Cookie
CVSS 9.8
CVE-2022-50926
CRITICAL
WAGO 750-8212 PFC200 G2 2ETH RS - Privilege Escalation
CVSS 9.8
CVE-2022-3083
LOW
Landis+Gyr E850 (ZMQ200) - Info Disclosure
CVSS 3.9
CVE-2022-38297
CRITICAL
UCMS v1.6.0 - Authentication Bypass via Cookie Poisoning
CVSS 9.8
CVE-2022-36032
MEDIUM
ReactPHP HTTP 0.7.0-1.7.0 - Cookie Prefix Spoofing via URL Decoding
CVSS 5.3
CVE-2022-2615
MEDIUM
Google Chrome <104.0.5112.79 - CSRF
CVSS 6.5
CVE-2022-35284
HIGH
IBM Security Verify Information Queue 10.0.2 - Info Disclosure
CVSS 7.5
CVE-2022-30620
HIGH
Cellinx Camera - Privilege Escalation
CVSS 8.2
CVE-2022-29248
HIGH
Guzzle < 6.5.6 - Cookie Domain Validation Bypass
CVSS 8.0
CVE-2022-22785
MEDIUM
Zoom Meetings < 5.10.0 - Session Cookie Spoofing via Improper Domain Validation
CVSS 5.9
CVE-2022-28113
HIGH
FANTEC GmbH MWiD25-DS Firmware <2.000.030 - RCE
CVSS 7.2
CVE-2022-1148
MEDIUM
GitLab CE/EE <14.7.7-14.9.2 - Info Disclosure
CVSS 5.3
CVE-2021-47706
HIGH
COMMAX Biometric Access Control System 1.0.0 - Auth Bypass
CVE-2021-20450
MEDIUM
IBM Cognos Controller <11.0.0 - Open Redirect
CVSS 4.3
CVE-2021-36338
MEDIUM
Unisphere for PowerMax <9.2.2.2 - Privilege Escalation
CVSS 6.3
CVE-2021-41819
HIGH
Ruby CGI < 2.6.8 and CGI Gem < 0.3.1 - Cookie Security Prefix Bypass
CVSS 7.5
CVE-2021-41263
HIGH
rails_multisite <4 - Info Disclosure
CVSS 8.3
CVE-2021-3818
MEDIUM
Grav < 1.7.22 - Reliance on Cookies without Validation and Integrity Checking
CVSS 5.3
CVE-2021-33842
HIGH
Circutor SGE-PLC1000 <0.9.2b - Auth Bypass
CVSS 8.8
CVE-2021-29624
MEDIUM
fastify-csrf < 3.1.0 - Cross-Site Request Forgery Protection Bypass via Subdomain Cookie Handling
CVSS 6.5
Details
Vulnerabilities
74