Skip to main content

CWE archive

CWE-565 CVEs

Programmatic archive

75 CVEs tagged with CWE-56520 Critical, 26 High, 26 Medium, 3 Low, 0 Unrated.

CVE-2026-53871

Published Jun 17, 2026

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile…

CVSS 8.6 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-8337

Published May 21, 2026

Concrete CMS 9.5.0 and below is vulnerable to IDOR in surveys. To be vulnerable, a site would have to be configured in such a way that both public and private surveys are present…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-39963

Published Apr 15, 2026

Serendipity is a PHP-powered weblog engine. In versions 2.6-beta2 and below, the serendipity_setCookie() function in include/functions_config.inc.php uses $_SERVER['HTTP_HOST'] w…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-39324

Published Apr 7, 2026

Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secre…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-5130

Published Mar 30, 2026

The Debugger & Troubleshooter plugin for WordPress was vulnerable to Unauthenticated Privilege Escalation in versions up to and including 1.3.2. This was due to the plugin accepti…

CVSS 8.8 · High
evidence mentions
4
Buzz score
22.6

CVE-2022-50926

Published Jan 13, 2026

WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's…

CVSS 8.7 · High

CVE-2025-65212

Published Jan 6, 2026

An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacke…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-14440

Published Dec 13, 2025

The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2021-47706

Published Dec 9, 2025

COMMAX Biometric Access Control System 1.0.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access sensitive information and circumvent p…

CVSS 8.7 · High

CVE-2025-64447

Published Dec 9, 2025

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48980

Published Oct 31, 2025

In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie at…

CVSS 6.5 · Medium

CVE-2025-31120

Published Apr 18, 2025

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, an insecure view count mechanism in the forum page allows an unaut…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2395

Published Mar 17, 2025

The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to use a particular API and alter cookies to log in as…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2024-9970

Published Oct 15, 2024

The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tam…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-9820

Published Oct 15, 2024

The WP 2FA with Telegram plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in versions up to, and including, 3.0. This is due to the two-factor code being sto…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21583

Published Jul 19, 2024

Versions of the package github.com/gitpod-io/gitpod/components/server/go/pkg/lib before main-gha.27122; versions of the package github.com/gitpod-io/gitpod/components/ws-proxy/pkg…

CVSS 4.1 · Medium

CVE-2024-39734

Published Jul 14, 2024

IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-0947

Published Jun 27, 2024

Reliance on Cookies without Validation and Integrity Checking vulnerability in Talya Informatics Elektraweb allows Session Credential Falsification through Manipulation, Accessing…

CVSS 9.8 · Critical

CVE-2021-20450

Published May 3, 2024

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by se…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-22186

Published Apr 18, 2024

The application suffers from a privilege escalation vulnerability. An attacker logged in as guest can escalate his privileges by poisoning the cookie to become administrator.

CVSS 8.7 · High

CVE-2024-21872

Published Apr 18, 2024

The device allows an unauthenticated attacker to bypass authentication and modify the cookie to reveal hidden pages that allows more critical operations to the transmitter.

CVSS 8.7 · High
Showing 1-25 of 75 CVEsPage 1 of 3