Skip to content
Noroxi

CWE-384 · 417 records

Session Fixation

CVEs in this class

417 records

  • An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0

    CriticalCVSS 9.8Proof of conceptEPSS 68%

    tp-link · tl-wr840n firmwareJun 4, 2018

  • Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    CriticalCVSS 9.8Proof of conceptEPSS 31%

    gogs · gogsNov 4, 2018

  • Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    apache2triad · apache2triadAug 23, 2017

  • Weak Session ID Check in the OmniAccess Stellar Web Management Interface

    CriticalCVSS 9.8Proof of conceptEPSS 14%

    alcatel-lucent · omniaccess stellar productsJul 16, 2025

  • Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co

    HighCVSS 8.8Proof of conceptEPSS 19%

    zohocorp · servicedesk plusApr 24, 2019

  • In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

    CriticalCVSS 9.8Proof of conceptEPSS 7%

    moodle · moodleMar 6, 2023

  • REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i

    CriticalCVSS 9.8No exploitEPSS 4%

    rest-client project · rest-clientAug 9, 2017

  • clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    clonos · clonosOct 24, 2019

  • VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and

    CriticalCVSS 9.8No exploitEPSS 3%

    vmware · vcloud directorApr 1, 2019

  • Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.

    CriticalCVSS 9.8No exploitEPSS 3%

    gitea · giteaNov 4, 2018

  • Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we

    CriticalCVSS 9.8No exploitEPSS 3%

    unit4 · teta webAug 2, 2017

  • Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by

    CriticalCVSS 9.8No exploitEPSS 3%

    revive-adserver · revive adserverMar 27, 2017

  • TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper

    CriticalCVSS 9.8No exploitEPSS 2%

    mitsubishielectric · iu1-1m20-d firmwareMar 15, 2020

  • In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

    CriticalCVSS 9.8No exploitEPSS 2%

    apache · airflowSep 2, 2022

  • The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta

    CriticalCVSS 9.8No exploitEPSS 2%

    simplesamlphp · simplesamlphpSep 1, 2017

  • A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code

    CriticalCVSS 9.8No exploitEPSS 2%

    phpgurukul · hospital management systemMay 11, 2023

  • VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.

    CriticalCVSS 9.8No exploitEPSS 2%

    vmware · vrealize automationApr 13, 2018

  • A flaw was found in Infinispan through version 9.4.14.Final.

    CriticalCVSS 9.8No exploitEPSS 2%

    infinispan · infinispanJan 2, 2020

  • Session fixation vulnerability in D-Link DIR-600L routers (rev.

    CriticalCVSS 9.8No exploitEPSS 2%

    d-link · dir-600l firmwareSep 7, 2017

  • An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.

    CriticalCVSS 9.8No exploitEPSS 2%

    davical · andrew\'s web librariesApr 15, 2020

  • Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

    CriticalCVSS 9.8Proof of conceptEPSS 2%

    Apr 18, 2025

  • Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.

    CriticalCVSS 10.0No exploitEPSS 2%

    trendnet · tew-827dru firmwareDec 30, 2021

  • SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth

    CriticalCVSS 9.8No exploitEPSS 2%

    simplesamlphp · simplesamlphpSep 1, 2017

  • An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code

    CriticalCVSS 9.8No exploitEPSS 2%

    chinamobile · intelligent home gateway firmwareSep 5, 2023

  • Certain NetModule devices allow Limited Session Fixation via PHPSESSID.

    CriticalCVSS 9.8No exploitEPSS 2%

    netmodule · netmodule router softwareAug 23, 2021

All vulnerability classes