CWE-602: CWE-602
Yearly Trend
Top Affected Vendors
All CWE-602 CVEs (40)
A command injection vulnerability in the web interface ping tool of Siemens RUGGEDCOM ROX devices allows authenticated remote attackers to execute arb...
May 13, 2025This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on affected RUGGEDCOM ROX devices through comm...
May 13, 2025CVE-2025-51682 is a client-side authorization vulnerability in mJobtime 15.7.2 that allows attackers to bypass authentication and gain administrative ...
Dec 1, 2025CVE-2025-10640 allows unauthenticated attackers to bypass authentication on WorkExaminer Professional servers by exploiting missing server-side valida...
Oct 21, 2025A logic vulnerability in the Transsion AppLock mobile application allows attackers to bypass the application password protection. This affects users o...
Dec 13, 2024This vulnerability allows authenticated Advanced Users to elevate their privileges to Administrator by exploiting insufficient server-side permission ...
Jan 14, 2022This vulnerability in Orban Optimod audio processors allows remote attackers to escalate privileges by manipulating client-side browser storage that c...
Oct 6, 2025Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service on TCP port 1069 that allows management operations. The vulnerability allows at...
Sep 18, 2025This vulnerability allows attackers to bypass server-side security controls in Fortinet FortiSandbox by manipulating client-side HTTP requests, enabli...
May 14, 2024This vulnerability in CyberArk products involves client-side enforcement of server-side security (CWE-602), allowing attackers to bypass intended secu...
Aug 25, 2024CVE-2025-25497 is a client-side validation bypass vulnerability in Netsweeper Server that allows attackers to reassign account ownership without autho...
Mar 6, 2025This vulnerability allows a local authenticated user with monitor role privileges in Dell Unisphere for PowerMax to bypass authorization controls and ...
Apr 30, 2021CVE-2025-32808 is a client-side access control vulnerability in W. W. Norton InQuizitive that allows students to insert arbitrary records of their qui...
Apr 11, 2025The SKT PayPal for WooCommerce WordPress plugin has a payment bypass vulnerability that allows unauthenticated attackers to complete purchases without...
Nov 27, 2025The WPC Name Your Price for WooCommerce WordPress plugin allows unauthenticated attackers to purchase products at arbitrary prices even when custom pr...
Oct 31, 2025The Order Tip for WooCommerce WordPress plugin has an unauthenticated input validation vulnerability that allows attackers to manipulate tip amounts. ...
Aug 15, 2025CVE-2025-47697 is an authentication bypass vulnerability in wivia 5 where client-side security controls can be manipulated to bypass server-side authe...
May 30, 2025IBM Aspera Faspex versions 5.0.0 through 5.0.12 have a client-side security enforcement vulnerability that allows authenticated users to bypass server...
May 22, 2025This vulnerability allows authenticated remote attackers to elevate privileges to Administrator level for limited functions in Cisco Unified Intellige...
May 21, 2025This vulnerability allows authenticated remote attackers to bypass security restrictions in Ivanti Connect Secure's Secure Application Manager. It aff...
Dec 10, 2024IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 have a client-side security control bypass vulnerability where authenticated users can perform unaut...
Jul 31, 2025This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to bypass client-side validation in the authoring interface, po...
May 3, 2025CVE-2025-28168 is an unrestricted file upload vulnerability in the Multiple File Upload add-on for OutSystems. Attackers can bypass client-side file v...
May 5, 2025This vulnerability allows authenticated administrators with read-only permissions to modify restricted settings in Ivanti Connect Secure and Ivanti Po...
Jul 8, 2025A privilege escalation vulnerability in SINEMA Remote Connect Server allows authenticated local users with self-management privileges to modify users ...
Jul 9, 2024This CVE describes an out-of-bounds data read vulnerability in Huawei's authorization module that could allow attackers to read unauthorized memory co...
May 6, 2025This vulnerability in lumasoft fotoShare Cloud allows unauthenticated attackers to bypass password protection on photo albums due to client-side valid...
Aug 27, 2025This vulnerability allows privileged operators in Gallagher Command Centre Server to bypass expiry checks when entering competency data due to client-...
Oct 23, 2025This vulnerability in IBM SmartCloud Analytics - Log Analysis allows a local authenticated attacker to bypass client-side security controls to manipul...
Jul 23, 2025The Spin Wheel WordPress plugin allows unauthenticated attackers to manipulate prize selection by modifying client-side parameters. This vulnerability...
Jan 17, 2026This vulnerability allows unauthenticated attackers to bypass payment requirements in the Hydra Booking WordPress plugin. Attackers can confirm bookin...
Nov 11, 2025This vulnerability allows authenticated users to bypass client-side validation in IBM OpenPages with Watson, enabling them to save GRC Objects without...
Jul 8, 2025This vulnerability in the Wp Ultimate Review WordPress plugin allows attackers to manipulate review scores by bypassing server-side security checks th...
May 17, 2024This vulnerability in the Zero Spam WordPress plugin allows attackers to bypass spam protection mechanisms by exploiting client-side enforcement of se...
May 17, 2024This vulnerability in IBM Cloud Pak for Business Automation allows attackers to perform unauthorized actions or access restricted content through man-...
Nov 3, 2025This vulnerability in Axis Camera Station Pro allows authenticated users to edit or delete camera views without proper authorization due to insufficie...
Nov 26, 2024IBM Db2 Intelligence Center versions 1.1.0 through 1.1.2 contain a client-side enforcement vulnerability where security mechanisms that should be enfo...
Dec 26, 2025This vulnerability in LitmusChaos Litmus allows attackers to bypass server-side security controls through client-side manipulation. It affects LitmusC...
Aug 10, 2025IBM ApplinX 11.1 has a client-side security enforcement vulnerability that allows authenticated users to perform unauthorized administrative actions o...
Jan 20, 2026This vulnerability allows privileged users in IBM Controller/Cognos Controller to bypass server-side security validation by manipulating client-side i...
Dec 8, 2025About CWE-602 (CWE-602)
Our database tracks 40 CVEs classified as CWE-602, with 6 rated critical and 14 rated high severity. The average CVSS score for CWE-602 vulnerabilities is 6.8.
External reference: View CWE-602 on MITRE CWE →
Monitor CWE-602 Vulnerabilities
Get alerted when new CWE-602 CVEs affect your infrastructure.
Start Monitoring Free