The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.
Volume of CVEs assigned to CWE-602 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
147 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-64813CRITICAL In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session | Jul 23, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-14109CRITICAL Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox | Jun 30, 2026 | 9.6 | 39 | NO | NO |
CVE-2026-14041HIGH Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium secur | Jun 30, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-14086HIGH Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security sever | Jun 30, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-14036HIGH Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium se | Jun 30, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-42266HIGH JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.0.0 to 4.5.6, the allow-list of extensions th | May 13, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-42160CRITICAL Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. From version 2.1.1 to before version 7.3.2, there is insuffic | May 8, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-46485HIGH Dashy is a self-hostable personal dashboard. Prior to 4.0.8, Dashy deployments using OIDC can allow unauthenticated users or non-admin authenticated users to write changes to the m | Jul 15, 2026 | 8.2 | 35 | NO | NO |
CVE-2026-13903HIGH Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium se | Jun 30, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-13901CRITICAL Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbo | Jun 30, 2026 | 9.6 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.