Reference page — cumulative record through Thursday, October 8, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-614
Weakness type CWE-614 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 16 | 15 | 0 |
Monthly trend
▂▁▁▁▁▁▁▁▁▁▂█▄▃▁▃
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 1 · 2026-06 7 · 2026-07 3 · 2026-08 2 · 2026-09 0 · 2026-10 2
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-41017 | 5.9 | 29.4 | — | Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-ter… |
| CVE-2026-65655 | 2.3 | 29.1 | — | Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-termina… |
| CVE-2026-43828 | 5.9 | 24.2 | — | Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set… |
| CVE-2026-53661 | 8.8 | 22.8 | — | boruta-server sent sensitive session cookies without the Secure attribute |
| CVE-2026-48058 | 4.6 | 22.8 | — | nebula-mesh: Session and OIDC state cookies lack the Secure attribute |
| CVE-2026-46398 | 8.8 | 17.5 | — | HAX CMS Missing Secure Flag on Cookie |
| CVE-2025-8037 | 9.1 | 13.1 | — | Nameless cookies shadow secure cookies |
| CVE-2026-57948 | 7.6 | 9.2 | — | Pinpoint - Insecure Session Cookie Attributes in pinpointJwt |
| CVE-2026-11956 | 6.3 | 8.1 | — | TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute |
| CVE-2026-15656 | 4.3 | 7.6 | — | IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to mult… |
| CVE-2026-46550 | 5.4 | 4.5 | — | NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags |
| CVE-2026-56581 | 2.6 | 3.9 | — | HCL MyCloud was affected with Cookie Attribute Path Not Set |
| CVE-2024-23572 | 4.2 | 2.3 | — | — |
| CVE-2026-66249 | 3.1 | 0.9 | — | HCL iControl is affected by a Missing Secure Attribute vulnerability |
| CVE-2025-52608 | 4.3 | 0.7 | — | HCL iControl was affected by Missing Cookie Attributes vulnerability. |
| CVE-2026-56599 | 2.2 | 0.0 | — | HCL BigFix Service Management is affected by multiple security vulnerabilities. |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 2 |
| hcl software | 2 |
| hclsoftware | 2 |
| haxtheweb | 1 |
| hcl | 1 |
| ibm | 1 |
| juev | 1 |
| malach-it | 1 |
| mozilla | 1 |
| nocodb | 1 |
| pinpoint-apm | 1 |
| temporal technologies | 1 |
| twin | 1 |