İçeriğe atla
Noroxi

CWE-613 · 597 kayıt

Insufficient Session Expiration

Bu sınıftaki CVE’ler

597 kayıt

  • CVE-2014-2595
    44Planlayın

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication

    KritikCVSS 9,8Kavram kanıtıEPSS %17

    barracuda · web application firewall11 Şub 2020

  • CVE-2020-27422
    41Planlayın

    In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s

    KritikCVSS 9,8Kavram kanıtıEPSS %8

    anuko · time tracker16 Kas 2020

  • CVE-2021-24019
    40Planlayın

    An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke

    KritikCVSS 9,8Kavram kanıtıEPSS %4

    fortinet · forticlient endpoint management server6 Eki 2021

  • CVE-2020-8234
    40Planlayın

    A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g

    KritikCVSS 9,8İstismar yokEPSS %3

    ui · edgemax firmware21 Ağu 2020

  • CVE-2020-29667
    40Planlayın

    In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    lanatmservice · m3 atm monitoring system10 Ara 2020

  • CVE-2016-6545
    40Planlayın

    iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request

    KritikCVSS 9,8İstismar yokEPSS %3

    ieasytec · itrackeasy13 Tem 2018

  • CVE-2021-3311
    40Planlayın

    An issue was discovered in October through build 471.

    KritikCVSS 9,8İstismar yokEPSS %3

    octobercms · october5 Şub 2021

  • CVE-2018-21018
    40Planlayın

    Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

    KritikCVSS 9,8İstismar yokEPSS %3

    joinmastodon · mastodon22 Eyl 2019

  • CVE-2016-11014
    40Planlayın

    NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

    KritikCVSS 9,8İstismar yokEPSS %3

    netgear · jnr1010 firmware16 Eki 2019

  • CVE-2021-25981
    40Planlayın

    Talkyard - Insufficient Session Expiration

    KritikCVSS 9,8İstismar yokEPSS %2

    talkyard · talkyard3 Oca 2022

  • CVE-2020-35358
    40Planlayın

    DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %2

    domainmod · domainmod15 Mar 2021

  • CVE-2019-8149
    40Planlayın

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    KritikCVSS 9,8İstismar yokEPSS %2

    magento · magento5 Kas 2019

  • CVE-2020-27739
    40Planlayın

    A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u

    KritikCVSS 9,8İstismar yokEPSS %2

    citadel · webcit28 Eki 2020

  • CVE-2021-25992
    39İzleyin

    ifme - Insufficient Session Expiration

    KritikCVSS 9,8İstismar yokEPSS %2

    if-me · ifme10 Şub 2022

  • CVE-2020-27416
    39İzleyin

    Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c

    KritikCVSS 9,8İstismar yokEPSS %2

    mahadiscom · mahavitaran8 Ara 2021

  • CVE-2020-6649
    39İzleyin

    An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex

    KritikCVSS 9,8İstismar yokEPSS %2

    fortinet · fortiisolator8 Şub 2021

  • CVE-2021-38823
    39İzleyin

    The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.

    KritikCVSS 9,8İstismar yokEPSS %2

    icehrm · icehrm4 Eki 2021

  • CVE-2021-37333
    39İzleyin

    Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.

    KritikCVSS 9,8İstismar yokEPSS %1

    bookingcore · booking core4 Eki 2021

  • CVE-2018-6634
    39İzleyin

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access

    KritikCVSS 9,8İstismar yokEPSS %1

    parsecgaming · parsec7 May 2019

  • CVE-2016-5069
    39İzleyin

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

    KritikCVSS 9,8İstismar yokEPSS %1

    sierrawireless · aleos firmware9 Nis 2017

  • CVE-2021-40849
    39İzleyin

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a

    KritikCVSS 9,8İstismar yokEPSS %1

    mahara · mahara3 Kas 2021

  • CVE-2022-2713
    39İzleyin

    Insufficient Session Expiration in cockpit-hq/cockpit

    KritikCVSS 9,8İstismar yokEPSS %1

    agentejo · cockpit8 Ağu 2022

  • CVE-2021-36330
    39İzleyin

    Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.

    KritikCVSS 9,8İstismar yokEPSS %1

    dell · emc streaming data platform30 Kas 2021

  • CVE-2020-17474
    39İzleyin

    A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne

    KritikCVSS 9,8İstismar yokEPSS %1

    zkteco · zkbiosecurity server14 Ağu 2020

  • CVE-2015-5171
    39İzleyin

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic

    KritikCVSS 9,8İstismar yokEPSS %1

    cloudfoundry · cf-release24 Eki 2017

Tüm zafiyet sınıfları