Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass si
Insufficient policy enforcement in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass nav
NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that pe
The Spin Wheel plugin for WordPress is vulnerable to client-side prize manipulation in all versions up to, and including
The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versi
Insufficient policy enforcement in DevTools in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to bypass
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to 2.46.0,
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced
Insufficient policy enforcement in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced
Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass n
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attack
Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypa
Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attack
In WhatsUp Gold versions released before 2026.0.2, an improper authorization vulnerability in the Scheduled Reports API
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the c
IBM ApplinX 11.1 could allow an authenticated user to perform unauthorized administrative actions on the server due to s
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnera
Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F
In Quick.CMS, the administrative user interface restricts deletion of the primary language by omitting the corresponding
JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule en
Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and pa
MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Su
Frequently Asked Questions
What is CWE-602?
CWE-602 (CWE-602) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-602?
There are 76 CVE records associated with CWE-602 in our database. Of these, 7 are critical severity, 18 are high severity, and 43 are medium severity.
How can I protect against CWE-602 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-602 using AI-powered security agents.
Detect CWE-602 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-602 vulnerabilities across your infrastructure.
Get Started