The Secure attribute for sensitive cookies in HTTPS sessions is not set.
Volume of CVEs assigned to CWE-614 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46398HIGH HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set without the Secu | Jun 5, 2026 | 8.8 | 35 | NO | NO |
CVE-2026-53661HIGH Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session | Jun 11, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-57948MEDIUM Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secu | Jun 29, 2026 | 6.8 | 31 | NO | NO |
CVE-2026-41017MEDIUM Apache Airflow's `JWTRefreshMiddleware` set the JWT auth cookie without the `Secure` flag, so deployments running the Airflow API server behind an HTTPS-terminating reverse proxy ( | Jun 1, 2026 | 5.9 | 27 | NO | NO |
CVE-2026-43828MEDIUM Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute.
This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1.
| May 25, 2026 | 6.5 | 26 | NO | NO |
CVE-2026-1697MEDIUM The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web app of PcVue in version 12.0.0 through 16.3.3 included. | Feb 26, 2026 | 6.5 | 26 | NO | NO |
CVE-2025-8037CRITICAL Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set over HTTP and the shadowed cookie included the `Secure` attri | Jul 22, 2025 | 9.1 | 26 | NO | NO |
CVE-2026-46550MEDIUM NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the refresh-token cookie was set with httpOnly: true but missing both the secure flag and the sameSit | Jun 23, 2026 | 5.4 | 25 | NO | NO |
CVE-2018-25060HIGH A vulnerability was found in Macaron csrf and classified as problematic. Affected by this issue is some unknown functionality of the file csrf.go. The manipulation of the argument | Dec 30, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-4409HIGH Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository thorsten/phpmyfaq prior to 3.1.9. | Dec 11, 2022 | 7.5 | 25 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.