CVE-2021-40650Medium· 6.5▾ SunlitIn Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 6.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.7%
0.7% → 0.8%
In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the secure flag set.
connx = 6.2.0.1269Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-40649Medium· 6.5In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.
CVE-2026-92757Medium· 5.5Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may inadvertently disable field level encryption.
CVE-2026-92756Medium· 5.5Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this provider's encryption settings may silently lose TLS and schema-map settings leading to protected fields being stored une…
CVE-2017-6297Medium· 5.9The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server…
CVE-2023-28841Medium· 6.8Moby is an open source container framework developed by Docker Inc
CVE-2026-19891Low· 3.7A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02