CWE-488 · 37 records
Exposure of Data Element to Wrong Session
CVEs in this class
39 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2024-38367No exploit | CoacoaPods trunk sessions verification step could be manipulated for owner session hijackingcocoapods · trunk.cocoapods.org · CWE-488 | Critical9.6 | — | 11.1% | Jul 1, 2024 |
40Plan | CVE-2026-16326No exploit | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modehashicorp · tooling · CWE-488 | Critical10.0 | — | 0.5% | Jul 29, 2026 |
40Plan | CVE-2026-16498No exploit | terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modehashicorp · tooling · CWE-488 | Critical10.0 | — | 0.5% | Jul 28, 2026 |
39Monitor | CVE-2026-19931No exploit | Negotiate ambient user conn reusehaxx · curl · CWE-488 | Critical9.8 | — | 0.7% | Sep 6, 2026 |
36Monitor | CVE-2024-27455No exploit | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attemptsCWE-488 | Critical9.1 | — | 0.6% | Feb 26, 2024 |
36Monitor | CVE-2025-47928Proof of concept | Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`spotipy-dev · spotipy · CWE-488 | Critical9.1 | — | 0.6% | May 15, 2025 |
34Monitor | CVE-2026-86492No exploit | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokensjetbrains · youtrack · CWE-488 | High8.5 | — | 0.9% | Sep 7, 2026 |
33Monitor | CVE-2025-1247No exploit | Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instancered hat · red hat build of apache camel 4.8 for quarkus 3.15 · CWE-488 | High8.3 | — | 0.8% | Feb 13, 2025 |
33Monitor | CVE-2024-27935No exploit | Deno's Node.js Compatibility Runtime has Cross-Session Data Contaminationdeno · deno · CWE-488 | High8.3 | — | 0.7% | Mar 20, 2024 |
32Monitor | GHSA-82vp-jr39-4j2jNo exploit | TYPO3 Security Misconfiguration in Frontend Session HandlingPackagist · typo3/cms-core · CWE-488 | High8.2 | — | — | May 30, 2024 |
31Monitor | CVE-2024-6162No exploit | Undertow: url-encoded request path information can be broken on ajp-listenerred hat · eap 8.0.1 · CWE-488 | High7.5 | — | 1.7% | Jun 20, 2024 |
31Monitor | CVE-2022-40210No exploit | Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enabintel · data center manager · CWE-488 | High7.8 | — | 0.2% | May 10, 2023 |
30Monitor | CVE-2026-80231No exploit | native CA store conn reusehaxx · curl · CWE-488 | High7.5 | — | 0.9% | Sep 6, 2026 |
30Monitor | CVE-2026-5773No exploit | wrong reuse of SMB connectionhaxx · curl · CWE-488 | High7.5 | — | 0.7% | May 13, 2026 |
30Monitor | CVE-2024-5148No exploit | Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificatered hat · red hat enterprise linux 10 · CWE-488 | High7.5 | — | 0.6% | Sep 2, 2024 |
30Monitor | CVE-2023-6519No exploit | Seeing admin password hash value in Mia Technology's Mia-Medmiateknoloji · mia-med · CWE-488 | High7.5 | — | 0.5% | Feb 8, 2024 |
30Monitor | CVE-2023-1907No exploit | Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong sessionpgadmin · pgadmin · CWE-488 | High7.5 | — | 0.4% | Jan 9, 2025 |
30Monitor | CVE-2025-30073No exploit | An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.CWE-488 | High7.5 | — | 0.4% | Mar 26, 2025 |
29Monitor | CVE-2024-41977No exploit | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM siemens · ruggedcom rm1224 lte\(4g\) eu firmware · CWE-488 | High7.3 | — | 0.4% | Aug 13, 2024 |
29Monitor | CVE-2026-18489No exploit | IBM ContextForge Translate is affected by cross-client credential context confusionibm · contextforge · CWE-488 | High7.4 | — | 0.3% | Sep 4, 2026 |
29Monitor | CVE-2026-88017No exploit | rclone: FTP cross-session auth-proxy backend confusionrclone · rclone · CWE-488 | High7.3 | — | 0.2% | Sep 10, 2026 |
28Monitor | CVE-2026-23919No exploit | Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Serverzabbix · zabbix · CWE-488 | High7.1 | — | 0.2% | Mar 24, 2026 |
26Monitor | CVE-2026-8458No exploit | wrong reuse for different serviceshaxx · curl · CWE-488 | Medium6.5 | — | 0.4% | Jul 3, 2026 |
26Monitor | CVE-2026-23646No exploit | OpenProject users can delete other user's session, causing them to be logged outopenproject · openproject · CWE-488 | Medium6.5 | — | 0.4% | Jan 19, 2026 |
26Monitor | CVE-2026-84685No exploit | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managementauth0 · react-native-auth0 · CWE-488 | Medium6.5 | — | 0.3% | Sep 8, 2026 |
- CVE-2024-3836741Plan
CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking
CriticalCVSS 9.6No exploitEPSS 11%cocoapods · trunk.cocoapods.orgJul 1, 2024
- CVE-2026-1632640Plan
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
CriticalCVSS 10.0No exploitEPSS 1%hashicorp · toolingJul 29, 2026
- CVE-2026-1649840Plan
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
CriticalCVSS 10.0No exploitEPSS 0%hashicorp · toolingJul 28, 2026
- CVE-2026-1993139Monitor
Negotiate ambient user conn reuse
CriticalCVSS 9.8No exploitEPSS 1%haxx · curlSep 6, 2026
- CVE-2024-2745536Monitor
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts
CriticalCVSS 9.1No exploitEPSS 1%Feb 26, 2024
- CVE-2025-4792836Monitor
Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`
CriticalCVSS 9.1Proof of conceptEPSS 1%spotipy-dev · spotipyMay 15, 2025
- CVE-2026-8649234Monitor
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
HighCVSS 8.5No exploitEPSS 1%jetbrains · youtrackSep 7, 2026
- CVE-2025-124733Monitor
Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance
HighCVSS 8.3No exploitEPSS 1%red hat · red hat build of apache camel 4.8 for quarkus 3.15Feb 13, 2025
- CVE-2024-2793533Monitor
Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
HighCVSS 8.3No exploitEPSS 1%deno · denoMar 20, 2024
- GHSA-82vp-jr39-4j2j32Monitor
TYPO3 Security Misconfiguration in Frontend Session Handling
HighCVSS 8.2No exploitPackagist · typo3/cms-coreMay 30, 2024
- CVE-2024-616231Monitor
Undertow: url-encoded request path information can be broken on ajp-listener
HighCVSS 7.5No exploitEPSS 2%red hat · eap 8.0.1Jun 20, 2024
- CVE-2022-4021031Monitor
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enab
HighCVSS 7.8No exploitEPSS 0%intel · data center managerMay 10, 2023
- CVE-2026-8023130Monitor
native CA store conn reuse
HighCVSS 7.5No exploitEPSS 1%haxx · curlSep 6, 2026
- CVE-2026-577330Monitor
wrong reuse of SMB connection
HighCVSS 7.5No exploitEPSS 1%haxx · curlMay 13, 2026
- CVE-2024-514830Monitor
Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
HighCVSS 7.5No exploitEPSS 1%red hat · red hat enterprise linux 10Sep 2, 2024
- CVE-2023-651930Monitor
Seeing admin password hash value in Mia Technology's Mia-Med
HighCVSS 7.5No exploitEPSS 1%miateknoloji · mia-medFeb 8, 2024
- CVE-2023-190730Monitor
Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session
HighCVSS 7.5No exploitEPSS 0%pgadmin · pgadminJan 9, 2025
- CVE-2025-3007330Monitor
An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.
HighCVSS 7.5No exploitEPSS 0%Mar 26, 2025
- CVE-2024-4197729Monitor
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM
HighCVSS 7.3No exploitEPSS 0%siemens · ruggedcom rm1224 lte\(4g\) eu firmwareAug 13, 2024
- CVE-2026-1848929Monitor
IBM ContextForge Translate is affected by cross-client credential context confusion
HighCVSS 7.4No exploitEPSS 0%ibm · contextforgeSep 4, 2026
- CVE-2026-8801729Monitor
rclone: FTP cross-session auth-proxy backend confusion
HighCVSS 7.3No exploitEPSS 0%rclone · rcloneSep 10, 2026
- CVE-2026-2391928Monitor
Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server
HighCVSS 7.1No exploitEPSS 0%zabbix · zabbixMar 24, 2026
- CVE-2026-845826Monitor
wrong reuse for different services
MediumCVSS 6.5No exploitEPSS 0%haxx · curlJul 3, 2026
- CVE-2026-2364626Monitor
OpenProject users can delete other user's session, causing them to be logged out
MediumCVSS 6.5No exploitEPSS 0%openproject · openprojectJan 19, 2026
- CVE-2026-8468526Monitor
Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management
MediumCVSS 6.5No exploitEPSS 0%auth0 · react-native-auth0Sep 8, 2026