CWE-602: CWE-602

40
Total CVEs
6
Critical
14
High
6.8
Avg CVSS

Yearly Trend

2026
2
2025
28
2024
8
2022
1
2021
1

Top Affected Vendors

1 Ibm 9
2 Cisco 2
3 Ivanti 2
4 Wwnorton 1
5 Fortinet 1
6 Dell 1
7 Siemens 1
8 Huawei 1
9 Mjobtime 1
10 Cyberark 1

All CWE-602 CVEs (40)

CVE-2025-32469
9.9

A command injection vulnerability in the web interface ping tool of Siemens RUGGEDCOM ROX devices allows authenticated remote attackers to execute arb...

May 13, 2025
CVE-2025-33025
9.9

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on affected RUGGEDCOM ROX devices through comm...

May 13, 2025
CVE-2025-51682
9.8

CVE-2025-51682 is a client-side authorization vulnerability in mJobtime 15.7.2 that allows attackers to bypass authentication and gain administrative ...

Dec 1, 2025
CVE-2025-10640
9.8

CVE-2025-10640 allows unauthenticated attackers to bypass authentication on WorkExaminer Professional servers by exploiting missing server-side valida...

Oct 21, 2025
CVE-2024-12603
9.8

A logic vulnerability in the Transsion AppLock mobile application allows attackers to bypass the application password protection. This affects users o...

Dec 13, 2024
CVE-2022-20658
9.6

This vulnerability allows authenticated Advanced Users to elevate their privileges to Administrator by exploiting insufficient server-side permission ...

Jan 14, 2022
CVE-2025-61197
8.9

This vulnerability in Orban Optimod audio processors allows remote attackers to escalate privileges by manipulating client-side browser storage that c...

Oct 6, 2025
CVE-2025-53969
8.8

Cognex In-Sight Explorer and In-Sight Camera Firmware expose a service on TCP port 1069 that allows management operations. The vulnerability allows at...

Sep 18, 2025
CVE-2024-31491
8.8

This vulnerability allows attackers to bypass server-side security controls in Fortinet FortiSandbox by manipulating client-side HTTP requests, enabli...

May 14, 2024
CVE-2024-42340
8.3

This vulnerability in CyberArk products involves client-side enforcement of server-side security (CWE-602), allowing attackers to bypass intended secu...

Aug 25, 2024
CVE-2025-25497
8.1

CVE-2025-25497 is a client-side validation bypass vulnerability in Netsweeper Server that allows attackers to reassign account ownership without autho...

Mar 6, 2025
CVE-2021-21531
8.1

This vulnerability allows a local authenticated user with monitor role privileges in Dell Unisphere for PowerMax to bypass authorization controls and ...

Apr 30, 2021
CVE-2025-32808
7.7

CVE-2025-32808 is a client-side access control vulnerability in W. W. Norton InQuizitive that allows students to insert arbitrary records of their qui...

Apr 11, 2025
CVE-2025-7820
7.5

The SKT PayPal for WooCommerce WordPress plugin has a payment bypass vulnerability that allows unauthenticated attackers to complete purchases without...

Nov 27, 2025
CVE-2025-12115
7.5

The WPC Name Your Price for WooCommerce WordPress plugin allows unauthenticated attackers to purchase products at arbitrary prices even when custom pr...

Oct 31, 2025
CVE-2025-6025
7.5

The Order Tip for WooCommerce WordPress plugin has an unauthenticated input validation vulnerability that allows attackers to manipulate tip amounts. ...

Aug 15, 2025
CVE-2025-47697
7.5

CVE-2025-47697 is an authentication bypass vulnerability in wivia 5 where client-side security controls can be manipulated to bypass server-side authe...

May 30, 2025
CVE-2025-33137
7.1

IBM Aspera Faspex versions 5.0.0 through 5.0.12 have a client-side security enforcement vulnerability that allows authenticated users to bypass server...

May 22, 2025
CVE-2025-20113
7.1

This vulnerability allows authenticated remote attackers to elevate privileges to Administrator level for limited functions in Cisco Unified Intellige...

May 21, 2025
CVE-2024-9844
7.1

This vulnerability allows authenticated remote attackers to bypass security restrictions in Ivanti Connect Secure's Secure Application Manager. It aff...

Dec 10, 2024
CVE-2025-36039
6.5

IBM Aspera Faspex versions 5.0.0 through 5.0.12.1 have a client-side security control bypass vulnerability where authenticated users can perform unaut...

Jul 31, 2025
CVE-2025-1838
6.5

This vulnerability in IBM Cloud Pak for Business Automation allows authenticated users to bypass client-side validation in the authoring interface, po...

May 3, 2025
CVE-2025-28168
6.4

CVE-2025-28168 is an unrestricted file upload vulnerability in the Multiple File Upload add-on for OutSystems. Attackers can bypass client-side file v...

May 5, 2025
CVE-2025-5450
6.3

This vulnerability allows authenticated administrators with read-only permissions to modify restricted settings in Ivanti Connect Secure and Ivanti Po...

Jul 8, 2025
CVE-2024-39870
6.3

A privilege escalation vulnerability in SINEMA Remote Connect Server allows authenticated local users with self-management privileges to modify users ...

Jul 9, 2024
CVE-2025-46591
6.2

This CVE describes an out-of-bounds data read vulnerability in Huawei's authorization module that could allow attackers to read unauthorized memory co...

May 6, 2025
CVE-2025-56694
5.8

This vulnerability in lumasoft fotoShare Cloud allows unauthenticated attackers to bypass password protection on photo albums due to client-side valid...

Aug 27, 2025
CVE-2025-41402
5.5

This vulnerability allows privileged operators in Gallagher Command Centre Server to bypass expiry checks when entering competency data due to client-...

Oct 23, 2025
CVE-2024-41750
5.5

This vulnerability in IBM SmartCloud Analytics - Log Analysis allows a local authenticated attacker to bypass client-side security controls to manipul...

Jul 23, 2025
CVE-2026-0808
5.3

The Spin Wheel WordPress plugin allows unauthenticated attackers to manipulate prize selection by modifying client-side parameters. This vulnerability...

Jan 17, 2026
CVE-2025-12788
5.3

This vulnerability allows unauthenticated attackers to bypass payment requirements in the Hydra Booking WordPress plugin. Attackers can confirm bookin...

Nov 11, 2025
CVE-2025-27367
5.3

This vulnerability allows authenticated users to bypass client-side validation in IBM OpenPages with Watson, enabling them to save GRC Objects without...

Jul 8, 2025
CVE-2024-32685
5.3

This vulnerability in the Wp Ultimate Review WordPress plugin allows attackers to manipulate review scores by bypassing server-side security checks th...

May 17, 2024
CVE-2024-32521
5.3

This vulnerability in the Zero Spam WordPress plugin allows attackers to bypass spam protection mechanisms by exploiting client-side enforcement of se...

May 17, 2024
CVE-2025-36093
4.8

This vulnerability in IBM Cloud Pak for Business Automation allows attackers to perform unauthorized actions or access restricted content through man-...

Nov 3, 2025
CVE-2024-6831
4.4

This vulnerability in Axis Camera Station Pro allows authenticated users to edit or delete camera views without proper authorization due to insufficie...

Nov 26, 2024
CVE-2025-14687
4.3

IBM Db2 Intelligence Center versions 1.1.0 through 1.1.2 contain a client-side enforcement vulnerability where security mechanisms that should be enfo...

Dec 26, 2025
CVE-2025-8792
4.3

This vulnerability in LitmusChaos Litmus allows attackers to bypass server-side security controls through client-side manipulation. It affects LitmusC...

Aug 10, 2025
CVE-2025-36410
3.1

IBM ApplinX 11.1 has a client-side security enforcement vulnerability that allows authenticated users to perform unauthorized administrative actions o...

Jan 20, 2026
CVE-2025-36102
2.7

This vulnerability allows privileged users in IBM Controller/Cognos Controller to bypass server-side security validation by manipulating client-side i...

Dec 8, 2025

About CWE-602 (CWE-602)

Our database tracks 40 CVEs classified as CWE-602, with 6 rated critical and 14 rated high severity. The average CVSS score for CWE-602 vulnerabilities is 6.8.

External reference: View CWE-602 on MITRE CWE →

Monitor CWE-602 Vulnerabilities

Get alerted when new CWE-602 CVEs affect your infrastructure.

Start Monitoring Free