Skip to content
Noroxi

CWE-488 · 37 records

Exposure of Data Element to Wrong Session

CVEs in this class

39 records

  • CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking

    CriticalCVSS 9.6No exploitEPSS 11%

    cocoapods · trunk.cocoapods.orgJul 1, 2024

  • consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    CriticalCVSS 10.0No exploitEPSS 1%

    hashicorp · toolingJul 29, 2026

  • terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    CriticalCVSS 10.0No exploitEPSS 0%

    hashicorp · toolingJul 28, 2026

  • Negotiate ambient user conn reuse

    CriticalCVSS 9.8No exploitEPSS 1%

    haxx · curlSep 6, 2026

  • In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts

    CriticalCVSS 9.1No exploitEPSS 1%

    Feb 26, 2024

  • Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`

    CriticalCVSS 9.1Proof of conceptEPSS 1%

    spotipy-dev · spotipyMay 15, 2025

  • In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

    HighCVSS 8.5No exploitEPSS 1%

    jetbrains · youtrackSep 7, 2026

  • CVE-2025-1247
    33Monitor

    Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance

    HighCVSS 8.3No exploitEPSS 1%

    red hat · red hat build of apache camel 4.8 for quarkus 3.15Feb 13, 2025

  • Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination

    HighCVSS 8.3No exploitEPSS 1%

    deno · denoMar 20, 2024

  • TYPO3 Security Misconfiguration in Frontend Session Handling

    HighCVSS 8.2No exploit

    Packagist · typo3/cms-coreMay 30, 2024

  • CVE-2024-6162
    31Monitor

    Undertow: url-encoded request path information can be broken on ajp-listener

    HighCVSS 7.5No exploitEPSS 2%

    red hat · eap 8.0.1Jun 20, 2024

  • Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enab

    HighCVSS 7.8No exploitEPSS 0%

    intel · data center managerMay 10, 2023

  • native CA store conn reuse

    HighCVSS 7.5No exploitEPSS 1%

    haxx · curlSep 6, 2026

  • CVE-2026-5773
    30Monitor

    wrong reuse of SMB connection

    HighCVSS 7.5No exploitEPSS 1%

    haxx · curlMay 13, 2026

  • CVE-2024-5148
    30Monitor

    Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate

    HighCVSS 7.5No exploitEPSS 1%

    red hat · red hat enterprise linux 10Sep 2, 2024

  • CVE-2023-6519
    30Monitor

    Seeing admin password hash value in Mia Technology's Mia-Med

    HighCVSS 7.5No exploitEPSS 1%

    miateknoloji · mia-medFeb 8, 2024

  • CVE-2023-1907
    30Monitor

    Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session

    HighCVSS 7.5No exploitEPSS 0%

    pgadmin · pgadminJan 9, 2025

  • An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.

    HighCVSS 7.5No exploitEPSS 0%

    Mar 26, 2025

  • A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM

    HighCVSS 7.3No exploitEPSS 0%

    siemens · ruggedcom rm1224 lte\(4g\) eu firmwareAug 13, 2024

  • IBM ContextForge Translate is affected by cross-client credential context confusion

    HighCVSS 7.4No exploitEPSS 0%

    ibm · contextforgeSep 4, 2026

  • rclone: FTP cross-session auth-proxy backend confusion

    HighCVSS 7.3No exploitEPSS 0%

    rclone · rcloneSep 10, 2026

  • Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

    HighCVSS 7.1No exploitEPSS 0%

    zabbix · zabbixMar 24, 2026

  • CVE-2026-8458
    26Monitor

    wrong reuse for different services

    MediumCVSS 6.5No exploitEPSS 0%

    haxx · curlJul 3, 2026

  • OpenProject users can delete other user's session, causing them to be logged out

    MediumCVSS 6.5No exploitEPSS 0%

    openproject · openprojectJan 19, 2026

  • Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management

    MediumCVSS 6.5No exploitEPSS 0%

    auth0 · react-native-auth0Sep 8, 2026

All vulnerability classes