CWE-384 · 417 records
Session Fixation
CVEs in this class
417 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
59Plan | CVE-2018-11714Proof of concept | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Critical9.8 | — | 68.1% | Jun 4, 2018 |
48Plan | CVE-2018-18925Proof of concept | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Critical9.8 | — | 31.1% | Nov 4, 2018 |
44Plan | CVE-2017-12965Proof of concept | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.apache2triad · apache2triad · CWE-384 | Critical9.8 | — | 15.7% | Aug 23, 2017 |
43Plan | CVE-2025-52689Proof of concept | Weak Session ID Check in the OmniAccess Stellar Web Management Interfacealcatel-lucent · omniaccess stellar products · CWE-384 | Critical9.8 | — | 13.5% | Jul 16, 2025 |
41Plan | CVE-2019-10008Proof of concept | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically cozohocorp · servicedesk plus · CWE-384 | High8.8 | — | 19.4% | Apr 24, 2019 |
41Plan | CVE-2021-36394Proof of concept | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.moodle · moodle · CWE-384 | Critical9.8 | — | 7.0% | Mar 6, 2023 |
40Plan | CVE-2015-1820No exploit | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie irest-client project · rest-client · CWE-384 | Critical9.8 | — | 4.3% | Aug 9, 2017 |
40Plan | CVE-2019-18418Proof of concept | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no seclonos · clonos · CWE-384 | Critical9.8 | — | 4.0% | Oct 24, 2019 |
40Plan | CVE-2019-5523No exploit | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and vmware · vcloud director · CWE-384 | Critical9.8 | — | 3.3% | Apr 1, 2019 |
40Plan | CVE-2018-18926No exploit | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.gitea · gitea · CWE-384 | Critical9.8 | — | 3.0% | Nov 4, 2018 |
40Plan | CVE-2015-1174No exploit | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack weunit4 · teta web · CWE-384 | Critical9.8 | — | 2.9% | Aug 2, 2017 |
40Plan | CVE-2016-9125No exploit | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, byrevive-adserver · revive adserver · CWE-384 | Critical9.8 | — | 2.7% | Mar 27, 2017 |
40Plan | CVE-2020-5543No exploit | TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not propermitsubishielectric · iu1-1m20-d firmware · CWE-384 | Critical9.8 | — | 2.2% | Mar 15, 2020 |
40Plan | CVE-2022-38054No exploit | In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.apache · airflow · CWE-384 | Critical9.8 | — | 2.1% | Sep 2, 2022 |
40Plan | CVE-2017-12868No exploit | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attasimplesamlphp · simplesamlphp · CWE-384 | Critical9.8 | — | 2.1% | Sep 1, 2017 |
40Plan | CVE-2023-31498No exploit | A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary codephpgurukul · hospital management system · CWE-384 | Critical9.8 | — | 2.1% | May 11, 2023 |
40Plan | CVE-2018-6959No exploit | VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.vmware · vrealize automation · CWE-384 | Critical9.8 | — | 2.0% | Apr 13, 2018 |
40Plan | CVE-2019-10158No exploit | A flaw was found in Infinispan through version 9.4.14.Final.infinispan · infinispan · CWE-384 | Critical9.8 | — | 2.0% | Jan 2, 2020 |
40Plan | CVE-2016-10405No exploit | Session fixation vulnerability in D-Link DIR-600L routers (rev.d-link · dir-600l firmware · CWE-384 | Critical9.8 | — | 1.9% | Sep 7, 2017 |
40Plan | CVE-2020-11729No exploit | An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.davical · andrew\'s web libraries · CWE-384 | Critical9.8 | — | 1.9% | Apr 15, 2020 |
40Plan | CVE-2025-28242Proof of concept | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.CWE-384 | Critical9.8 | — | 1.8% | Apr 18, 2025 |
40Plan | CVE-2021-20151No exploit | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.trendnet · tew-827dru firmware · CWE-384 | Critical10.0 | — | 1.6% | Dec 30, 2021 |
39Monitor | CVE-2017-12873No exploit | SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified othsimplesamlphp · simplesamlphp · CWE-384 | Critical9.8 | — | 1.7% | Sep 1, 2017 |
39Monitor | CVE-2023-41012No exploit | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code chinamobile · intelligent home gateway firmware · CWE-384 | Critical9.8 | — | 1.5% | Sep 5, 2023 |
39Monitor | CVE-2021-39290No exploit | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Critical9.8 | — | 1.5% | Aug 23, 2021 |
- CVE-2018-1171459Plan
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
CriticalCVSS 9.8Proof of conceptEPSS 68%tp-link · tl-wr840n firmwareJun 4, 2018
- CVE-2018-1892548Plan
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
CriticalCVSS 9.8Proof of conceptEPSS 31%gogs · gogsNov 4, 2018
- CVE-2017-1296544Plan
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
CriticalCVSS 9.8Proof of conceptEPSS 16%apache2triad · apache2triadAug 23, 2017
- CVE-2025-5268943Plan
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
CriticalCVSS 9.8Proof of conceptEPSS 14%alcatel-lucent · omniaccess stellar productsJul 16, 2025
- CVE-2019-1000841Plan
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co
HighCVSS 8.8Proof of conceptEPSS 19%zohocorp · servicedesk plusApr 24, 2019
- CVE-2021-3639441Plan
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
CriticalCVSS 9.8Proof of conceptEPSS 7%moodle · moodleMar 6, 2023
- CVE-2015-182040Plan
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i
CriticalCVSS 9.8No exploitEPSS 4%rest-client project · rest-clientAug 9, 2017
- CVE-2019-1841840Plan
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se
CriticalCVSS 9.8Proof of conceptEPSS 4%clonos · clonosOct 24, 2019
- CVE-2019-552340Plan
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and
CriticalCVSS 9.8No exploitEPSS 3%vmware · vcloud directorApr 1, 2019
- CVE-2018-1892640Plan
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
CriticalCVSS 9.8No exploitEPSS 3%gitea · giteaNov 4, 2018
- CVE-2015-117440Plan
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we
CriticalCVSS 9.8No exploitEPSS 3%unit4 · teta webAug 2, 2017
- CVE-2016-912540Plan
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by
CriticalCVSS 9.8No exploitEPSS 3%revive-adserver · revive adserverMar 27, 2017
- CVE-2020-554340Plan
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper
CriticalCVSS 9.8No exploitEPSS 2%mitsubishielectric · iu1-1m20-d firmwareMar 15, 2020
- CVE-2022-3805440Plan
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
CriticalCVSS 9.8No exploitEPSS 2%apache · airflowSep 2, 2022
- CVE-2017-1286840Plan
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta
CriticalCVSS 9.8No exploitEPSS 2%simplesamlphp · simplesamlphpSep 1, 2017
- CVE-2023-3149840Plan
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code
CriticalCVSS 9.8No exploitEPSS 2%phpgurukul · hospital management systemMay 11, 2023
- CVE-2018-695940Plan
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.
CriticalCVSS 9.8No exploitEPSS 2%vmware · vrealize automationApr 13, 2018
- CVE-2019-1015840Plan
A flaw was found in Infinispan through version 9.4.14.Final.
CriticalCVSS 9.8No exploitEPSS 2%infinispan · infinispanJan 2, 2020
- CVE-2016-1040540Plan
Session fixation vulnerability in D-Link DIR-600L routers (rev.
CriticalCVSS 9.8No exploitEPSS 2%d-link · dir-600l firmwareSep 7, 2017
- CVE-2020-1172940Plan
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.
CriticalCVSS 9.8No exploitEPSS 2%davical · andrew\'s web librariesApr 15, 2020
- CVE-2025-2824240Plan
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
CriticalCVSS 9.8Proof of conceptEPSS 2%Apr 18, 2025
- CVE-2021-2015140Plan
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.
CriticalCVSS 10.0No exploitEPSS 2%trendnet · tew-827dru firmwareDec 30, 2021
- CVE-2017-1287339Monitor
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth
CriticalCVSS 9.8No exploitEPSS 2%simplesamlphp · simplesamlphpSep 1, 2017
- CVE-2023-4101239Monitor
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code
CriticalCVSS 9.8No exploitEPSS 2%chinamobile · intelligent home gateway firmwareSep 5, 2023
- CVE-2021-3929039Monitor
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
CriticalCVSS 9.8No exploitEPSS 2%netmodule · netmodule router softwareAug 23, 2021