Skip to main content

CWE archive

CWE-1004 CVEs

Programmatic archive

42 CVEs tagged with CWE-10041 Critical, 15 High, 18 Medium, 8 Low, 0 Unrated.

CVE-2026-57948

Published Jun 29, 2026

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Sec…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-11956

Published Jun 11, 2026

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-42239

Published May 7, 2026

Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT session token is set with httpOnly: false at packages/backend-c…

CVSS 8.1 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39338

Published Apr 7, 2026

ChurchCRM is an open-source church management system. Prior to 7.1.0, a Blind Reflected Cross-Site Scripting vulnerability exists in the search parameter accepted by the ChurchCRM…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35575

Published Apr 7, 2026

ChurchCRM is an open-source church management system. Prior to 6.5.3, a Stored Cross-Site Scripting (Stored XSS) vulnerability in the admin panel’s group-creation feature allows a…

CVSS 8.0 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-25736

Published Feb 25, 2026

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 3…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-25735

Published Feb 25, 2026

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 3…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-25734

Published Feb 25, 2026

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 3…

CVSS 6.1 · Medium
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-25733

Published Feb 25, 2026

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 3…

CVSS 7.3 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-25136

Published Feb 25, 2026

Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scri…

CVSS 8.1 · High
evidence mentions
5
Buzz score
27.9
Vendor/product tagsBeta · best-effort

CVE-2026-0696

Published Jan 16, 2026

In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22081

Published Jan 9, 2026

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with th…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-27223

Published Oct 27, 2025

TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints such as /trufusionPortal/getProjectList. However, the applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-42909

Published Oct 14, 2025

SAP Cloud Appliance Library Appliances allows an attacker with high privileges to leverage an insecure S/4HANA default profile setting in an existing SAP CAL appliances to gain ac…

CVSS 3.0 · Low

CVE-2025-57424

Published Sep 29, 2025

A stored cross-site scripting (XSS) vulnerability exists in the MyCourts v3 application within the LTA number profile field. An attacker can insert arbitrary JavaScript into their…

CVSS 7.3 · High

CVE-2025-53757

Published Jul 16, 2025

This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A re…

CVSS 8.7 · High

CVE-2025-49189

Published Jun 12, 2025

The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-47289

Published Jun 2, 2025

CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered in CE Phoenix versions 1.0.9.9 through 1.1.0.2 where an atta…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-26844

Published May 8, 2025

An issue was discovered in Znuny through 7.1.3. A cookie is set without the HttpOnly flag.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-24318

Published Feb 28, 2025

Cookie policy is observable via built-in browser tools. In the presence of XSS, this could lead to full session compromise.

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-0479

Published Jan 20, 2025

This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used within its web interface. A remote attacker could exploit this vulnerability by inter…

CVSS 8.6 · High
evidence mentions
1
Buzz score
11.9

CVE-2024-47833

Published Oct 9, 2024

Taipy is an open-source Python library for easy, end-to-end application development for data scientists and machine learning engineers. In affected versions session cookies are se…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 42 CVEsPage 1 of 2