Skip to main content

CWE archive

CWE-315 CVEs

Programmatic archive

8 CVEs tagged with CWE-3152 Critical, 2 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2026-25818

Published Mar 13, 2026

HMS Networks Ewon Flexy with firmware before 15.0s4, Cosy+ with firmware 22.xx before 22.1s6, and Cosy+ with firmware 23.xx before 23.0s3 have weak entropy for authentication cook…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2025-8528

Published Aug 4, 2025

A vulnerability classified as problematic has been found in Exrick xboot up to 3.3.4. Affected is an unknown function of the file /xboot/permission/getMenuList. The manipulation l…

CVSS 2.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-4537

Published May 11, 2025

A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file ruoyi-ui/jsencrypt…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-41290

Published Oct 2, 2024

FlatPress CMS v1.3.1 1.3 was discovered to use insecure methods to store authentication data via the cookie's component.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8644

Published Sep 27, 2024

Cleartext Storage of Sensitive Information in a Cookie vulnerability in Oceanic Software ValeApp allows Protocol Manipulation, : JSON Hijacking (aka JavaScript Hijacking). This i…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-24768

Published Feb 5, 2024

1Panel is an open source Linux server operation and maintenance management panel. The HTTPS cookie that comes with the panel does not have the Secure keyword, which may cause the…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-8 of 8 CVEsPage 1 of 1