Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-565

Reliance on Cookies without Validation and Integrity Checking

The product relies on the existence or values of cookies when performing security-critical operations, but it does not properly ensure that the setting is valid for the associated user.

75
Assigned CVEs
200th
Commonality Rank
7.7
Avg CVSS
1.3%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-565 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2008
17 years ago
Most Recent CVE
Jun 17, 2026
37 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

75 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-0257CRITICAL
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establi
May 13, 20269.198YESYES
CVE-2023-35885CRITICAL
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
Jun 20, 20239.881NOYES
CVE-2017-6896HIGH
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Bas
Mar 14, 20178.839NOYES
CVE-2025-65212CRITICAL
An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the device's insufficient cookie verification, allowing an attacker
Jan 6, 20269.837NONO
CVE-2008-5784CRITICAL
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin cookie to 1.
Dec 31, 20089.837NOYES
CVE-2025-59247CRITICAL
Azure PlayFab Elevation of Privilege Vulnerability
Oct 9, 20259.835NONO
CVE-2022-50926CRITICAL
WAGO 750-8212 PFC200 G2 2ETH RS firmware contains a privilege escalation vulnerability that allows attackers to manipulate user session cookies. Attackers can modify the cookie's '
Jan 13, 20269.834NONO
CVE-2025-14440CRITICAL
The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.4.01. This is due to incorrect authentication checking in t
Dec 13, 20259.833NONO
CVE-2026-39324CRITICAL
Rack::Session is a session management implementation for Rack. From 2.0.0 to before 2.1.2, Rack::Session::Cookie incorrectly handles decryption failures when configured with secret
Apr 7, 20269.832NONO
CVE-2026-53871HIGH
Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile
Jun 17, 20268.131NONO
View all 75 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
8%
10%
4.0-4.9
12%
19%
5.0-5.9
13%
16%
6.0-6.9
11%
26%
7.0-7.9
24%
11%
8.0-8.9
29%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
1 CVE
1.3% of CVEs· 93rd percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
2.7% of CVEs· 91st percentile
ExploitDB
2 CVEs
2.7% of CVEs· 91st percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products