VulnSea

CWE-614

CVEs classified under CWE-614, newest first.

4 CVEsRSS

CVE-2026-65655None
1mo ago

When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-serv…

When OAuth authentication is enabled and browser-facing TLS terminates at a reverse proxy that forwards the callback to Temporal UI Server over HTTP, affected versions derive authentication-cookie Secure attributes from the proxy-to-serv…

SunlitEPSS 0.28%via NVD
CVE-2026-57948Medium· 6.8
2mo ago

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.co…

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.co…

SunlitEPSS 0.20%via NVD
CVE-2026-48058Medium
3mo ago

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

nebula-mesh: Session and OIDC state cookies lack the Secure attribute

Sunlitjuev · github.com/juev/nebula-meshEPSS 0.19%via GHSA
CVE-2026-1697Medium· 6.5
6mo ago

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included.

Sunlitarcinfo · pcvueEPSS 0.12%via NVD
CWE-614 vulnerabilities (CVEs) · VulnSea