CWE-602

Medium likelihood

Client-Side Enforcement of Server-Side Security

Parent: CWE-693 - Protection Mechanism Failure

The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

104 vulnerabilities with CWE-602
CVE-2025-2138 LOW
IBM Engineering Requirements Management Doors Next <7.1 - Privilege...
CVSS 3.5
CVE-2025-61197 HIGH
Orban Optimod <1.0.0.33-2.5.26 - Privilege Escalation
CVSS 8.9
CVE-2025-9495 HIGH
Vitogate 300 - Auth Bypass
CVE-2025-53969 HIGH
Cognex In-Sight - SSRF
CVSS 8.8
CVE-2025-56694 MEDIUM
lumasoft fotoShare Cloud <2025-03-13 - Info Disclosure
CVSS 5.8
CVE-2025-6025 HIGH
Order Tip for WooCommerce 1.5.4 - Unauthenticated SQL Injection
CVSS 7.5
CVE-2025-8792 MEDIUM
LitmusChaos Litmus <3.19.0 - XSS
CVSS 4.3
CVE-2025-54833 MEDIUM
OPEXUS FOIAXpress PAL <11.1.0 - Auth Bypass
CVSS 5.3
CVE-2025-36039 MEDIUM
IBM Aspera Faspex <5.0.12.1 - Privilege Escalation
CVSS 6.5
CVE-2025-6249 MEDIUM
FileZ client - Auth Bypass
CVSS 6.7
CVE-2025-27367 MEDIUM
IBM OpenPages with Watson 8.3-9.0 - Auth Bypass
CVSS 5.3
CVE-2025-5450 MEDIUM
Ivanti Connect/Ivanti Policy <22.7R2.8/<22.7R1.5 - Privilege Escala...
CVSS 6.3
CVE-2025-40591 HIGH
RUGGEDCOM ROX -<V2.16.5 - Info Disclosure
CVSS 7.7
CVE-2025-43699 MEDIUM
Salesforce OmniStudio <Spring 2025 - Auth Bypass
CVSS 5.3
CVE-2025-47697 HIGH
wivia <5 - Auth Bypass
CVSS 7.5
CVE-2025-33137 HIGH
IBM Aspera Faspex <5.0.12 - Info Disclosure
CVSS 7.1
CVE-2025-20113 HIGH
Cisco Unified Intelligence Center - Privilege Escalation
CVSS 7.1
CVE-2025-33025 CRITICAL
RUGGEDCOM ROX -<V2.16.5 - Path Traversal
CVSS 9.9
CVE-2025-33024 CRITICAL
RUGGEDCOM ROX -<V2.16.5 - Path Traversal
CVSS 9.9
CVE-2025-32469 CRITICAL
RUGGEDCOM ROX -<V2.16.5 - Info Disclosure
CVSS 9.9
CVE-2025-4527 LOW
Dígitro NGC Explorer 3.44.15 - Auth Bypass
CVSS 3.7
CVE-2025-46591 MEDIUM
Huawei HarmonyOS - Out-of-Bounds Read in Authorization Module
CVSS 6.2
CVE-2025-28168 MEDIUM
Multiple File Upload - Unrestricted File Upload
CVSS 6.4
CVE-2025-1838 MEDIUM
IBM Cloud Pak for Business Automation <24.0.1 - DoS
CVSS 6.5
CVE-2025-42601 HIGH
Meon KYC - Auth Bypass
Details
Vulnerabilities 104
Exploit Likelihood Medium