Skip to main content

CWE archive

CWE-614 CVEs

Programmatic archive

63 CVEs tagged with CWE-6141 Critical, 13 High, 39 Medium, 10 Low, 0 Unrated.

CVE-2026-48058

Published Jul 28, 2026

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/web/session.go and internal/web/oidc.go set HttpOnly and…

CVSS 4.6 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-56581

Published Jul 21, 2026

HCL MyCloud was affected with Cookie Attribute Path Not Set. It may increase the risk of unauthorized access to session data or authentication tokens.

CVSS 2.6 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23572

Published Jul 17, 2026

HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the contents of…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-57948

Published Jun 29, 2026

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Sec…

CVSS 7.6 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-46550

Published Jun 23, 2026

NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSi…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-53661

Published Jun 11, 2026

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session…

CVSS 8.8 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-11956

Published Jun 11, 2026

A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing…

CVSS 6.3 · Medium
evidence mentions
6
Buzz score
26.0

CVE-2026-46398

Published Jun 5, 2026

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set without the Sec…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2025-52608

Published Jun 4, 2026

HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and Sam…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41017

Published Jun 1, 2026

Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy…

CVSS 5.9 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-43828

Published May 25, 2026

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-22617

Published Apr 16, 2026

Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑t…

CVSS 5.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-4820

Published Apr 1, 2026

IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-32745

Published Mar 13, 2026

In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-58317

Published Dec 18, 2025

A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL requirements when setting administration cookies via web.config. The vulnerabilit…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36249

Published Oct 31, 2025

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie valu…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52614

Published Oct 12, 2025

HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to induce this event by feeding a user suitable links, either di…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-52632

Published Oct 10, 2025

A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue affects AION: 2.0.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-36011

Published Sep 9, 2025

IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie valu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-8037

Published Jul 22, 2025

Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attr…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-53757

Published Jul 16, 2025

This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure and HttpOnly flags on session cookies associated with the router web interface. A re…

CVSS 8.7 · High

CVE-2025-36026

Published Jun 28, 2025

IBM Datacap 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a htt…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10718

Published Mar 20, 2025

In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 63 CVEsPage 1 of 3