CVE-2024-44575
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to
CVSS
3.7
Low
EPSS
0.3%
p17
KEV
—
Exploit Today
5
0-100
Published: Sep 11, 2024 · Last modified: Jul 5, 2026 · CWE-732
0.3%EPSS · 30 days0.3%
2026-06-302026-07-20
RELY-PCIe v22.2.1 to v23.1.0 does not set the Secure attribute for sensitive cookies in HTTPS sessions, which could cause the user agent to send those cookies in cleartext over an HTTP session.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2021-341107.8 HIG63.5%
——19WinWaste.NET version 1.0.6183.16475 has incorrect permissions, allowing a local unprivileged user to replace the executable with a malicious file that will be executed with "LocalSystem" privileges.12dCVE-2017-176778.8 HIG60.5%
——18BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.12dCVE-2022-262817.5 HIG56.6%
——17BigAnt Server v5.6.06 was discovered to contain an incorrect access control issue.12dCVE-2023-317487.8 HIG53.5%
——16Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file.12dCVE-2023-390049.8 CRI52.0%
——16Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.12dCVE-2021-406496.5 MED51.7%
——16In Connx Version 6.2.0.1269 (20210623), a cookie can be issued by the application and not have the HttpOnly flag set.12d