Перейти к содержимому
Noroxi

CWE-324 · 25 записей

Use of a Key Past its Expiration Date

CVE этого класса

25 записей

  • CVE-2024-36031
    39Наблюдать

    keys: Fix overwrite of key expiration on instantiation

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    linux · linux kernel30 мая 2024 г.

  • CVE-2025-2291
    39Наблюдать

    PgBouncer default auth_query does not take Postgres password expiry into account

    КритическаяCVSS 9,8Эксплойта нетEPSS 0 %

    pgbouncer · pgbouncer16 апр. 2025 г.

  • CVE-2022-35401
    38Наблюдать

    An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230.

    ВысокаяCVSS 8,1Эксплойта нетEPSS 21 %

    asus · rt-ax82u firmware10 янв. 2023 г.

  • CVE-2026-39923
    36Наблюдать

    Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset

    КритическаяCVSS 9,2Эксплойта нетEPSS 0 %

    flarum · flarum framework5 авг. 2026 г.

  • CVE-2022-24732
    35Наблюдать

    Maddy Mail Server does not implement account expiry

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    maddy project · maddy9 мар. 2022 г.

  • CVE-2025-33012
    35Наблюдать

    IBM Db2 improper account lockout

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ibm · db27 нояб. 2025 г.

  • CVE-2025-31123
    34Наблюдать

    Zitadel Expired JWT Keys Usable for Authorization Grants

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    zitadel · zitadel31 мар. 2025 г.

  • CVE-2021-33020
    30Наблюдать

    Philips Vue PACS Use of a Key Past its Expiration Date

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    philips · myvue1 апр. 2022 г.

  • CVE-2023-6960
    30Наблюдать

    TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    sciener · ttlock app15 мар. 2024 г.

  • CVE-2025-13723
    30Наблюдать

    IBM Sterling Partner Engagement Manager Information Disclosure

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    ibm · sterling partner engagement manager13 мар. 2026 г.

  • CVE-2026-52809
    27Наблюдать

    Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

    СредняяCVSS 6,8Эксплойта нетEPSS 0 %

    gogs · gogs24 июн. 2026 г.

  • CVE-2022-2447
    26Наблюдать

    A flaw was found in Keystone.

    СредняяCVSS 6,6Эксплойта нетEPSS 1 %

    openstack · keystone1 сент. 2022 г.

  • CVE-2024-31895
    26Наблюдать

    IBM App Connect Enterprise information disclosure

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    ibm · app connect enterprise22 мая 2024 г.

  • CVE-2024-25679
    26Наблюдать

    In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by se

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    pquic · pquic9 февр. 2024 г.

  • CVE-2019-3790
    21Наблюдать

    Ops Manager uaa client issues tokens after refresh token expiration

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    pivotal software · operations manager6 июн. 2019 г.

  • CVE-2024-38277
    21Наблюдать

    moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    moodle · moodle18 июн. 2024 г.

  • CVE-2024-7318
    19Наблюдать

    Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity

    СредняяCVSS 4,8Эксплойта нетEPSS 0 %

    redhat · build of keycloak9 сент. 2024 г.

  • GHSA-57rh-gr4v-j5f6
    19Наблюдать

    Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date

    СредняяCVSS 4,8Эксплойта нет

    Maven · org.keycloak:keycloak-core9 сент. 2024 г.

  • CVE-2025-48813
    18Наблюдать

    Virtual Secure Mode Spoofing Vulnerability

    СредняяCVSS 4,7Эксплойта нетEPSS 0 %

    microsoft · windows 10 180914 окт. 2025 г.

  • CVE-2024-31894
    17Наблюдать

    IBM App Connect Enterprise information disclosure

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    ibm · app connect enterprise22 мая 2024 г.

  • CVE-2024-31893
    17Наблюдать

    IBM App Connect Enterprise information disclosure

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    ibm · app connect enterprise22 мая 2024 г.

  • CVE-2023-5342
    16Наблюдать

    Shim: expired secure boot certificate

    СредняяCVSS 4,1Эксплойта нетEPSS 0 %

    red hat · red hat enterprise linux 1014 авг. 2025 г.

  • CVE-2024-6299
    14Наблюдать

    Use of a Key Past its Expiration Date in Conduit

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    conduit · conduit25 июн. 2024 г.

  • CVE-2026-54787
    12Наблюдать

    sigstore-go fails to check signature timestamps against a signing key's validity period

    НизкаяCVSS 3,1Эксплойта нетEPSS 0 %

    sigstore · sigstore-go31 июл. 2026 г.

  • GHSA-3rw9-wmc8-8948
    10Наблюдать

    Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token

    НизкаяCVSS 2,5Эксплойта нет

    Go · github.com/coder/coder/v228 авг. 2025 г.

Все классы уязвимостей