CWE-613 · 608 records
Insufficient Session Expiration
CVEs in this class
608 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2014-2595Proof of concept | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authenticationbarracuda · web application firewall · CWE-613 | Critical9.8 | — | 16.9% | Feb 11, 2020 |
41Plan | CVE-2020-27422Proof of concept | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the sanuko · time tracker · CWE-613 | Critical9.8 | — | 7.9% | Nov 16, 2020 |
40Plan | CVE-2021-24019Proof of concept | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attackefortinet · forticlient endpoint management server · CWE-613 | Critical9.8 | — | 3.9% | Oct 6, 2021 |
40Plan | CVE-2020-8234No exploit | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Critical9.8 | — | 3.4% | Aug 21, 2020 |
40Plan | CVE-2020-29667Proof of concept | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, calanatmservice · m3 atm monitoring system · CWE-613 | Critical9.8 | — | 3.2% | Dec 10, 2020 |
40Plan | CVE-2016-6545No exploit | iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each requestieasytec · itrackeasy · CWE-613 | Critical9.8 | — | 3.0% | Jul 13, 2018 |
40Plan | CVE-2021-3311No exploit | An issue was discovered in October through build 471.octobercms · october · CWE-613 | Critical9.8 | — | 2.9% | Feb 5, 2021 |
40Plan | CVE-2018-21018No exploit | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Critical9.8 | — | 2.6% | Sep 22, 2019 |
40Plan | CVE-2016-11014No exploit | NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.netgear · jnr1010 firmware · CWE-613 | Critical9.8 | — | 2.5% | Oct 16, 2019 |
40Plan | CVE-2021-25981No exploit | Talkyard - Insufficient Session Expirationtalkyard · talkyard · CWE-613 | Critical9.8 | — | 2.5% | Jan 3, 2022 |
40Plan | CVE-2020-35358No exploit | DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.domainmod · domainmod · CWE-613 | Critical9.8 | — | 2.4% | Mar 15, 2021 |
40Plan | CVE-2019-8149No exploit | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Critical9.8 | — | 2.1% | Nov 5, 2019 |
40Plan | CVE-2020-27739No exploit | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in ucitadel · webcit · CWE-613 | Critical9.8 | — | 1.8% | Oct 28, 2020 |
39Monitor | CVE-2020-27416No exploit | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to cmahadiscom · mahavitaran · CWE-613 | Critical9.8 | — | 1.6% | Dec 8, 2021 |
39Monitor | CVE-2021-25992No exploit | ifme - Insufficient Session Expirationif-me · ifme · CWE-613 | Critical9.8 | — | 1.6% | Feb 10, 2022 |
39Monitor | CVE-2020-6649No exploit | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexfortinet · fortiisolator · CWE-613 | Critical9.8 | — | 1.5% | Feb 8, 2021 |
39Monitor | CVE-2021-38823No exploit | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.icehrm · icehrm · CWE-613 | Critical9.8 | — | 1.5% | Oct 4, 2021 |
39Monitor | CVE-2021-37333No exploit | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.bookingcore · booking core · CWE-613 | Critical9.8 | — | 1.5% | Oct 4, 2021 |
39Monitor | CVE-2018-6634No exploit | A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain accessparsecgaming · parsec · CWE-613 | Critical9.8 | — | 1.5% | May 7, 2019 |
39Monitor | CVE-2016-5069No exploit | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.sierrawireless · aleos firmware · CWE-613 | Critical9.8 | — | 1.4% | Apr 9, 2017 |
39Monitor | CVE-2021-40849No exploit | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited amahara · mahara · CWE-613 | Critical9.8 | — | 1.4% | Nov 3, 2021 |
39Monitor | CVE-2022-2713No exploit | Insufficient Session Expiration in cockpit-hq/cockpitagentejo · cockpit · CWE-613 | Critical9.8 | — | 1.3% | Aug 8, 2022 |
39Monitor | CVE-2021-36330No exploit | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.dell · emc streaming data platform · CWE-613 | Critical9.8 | — | 1.2% | Nov 30, 2021 |
39Monitor | CVE-2020-17474No exploit | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary nezkteco · zkbiosecurity server · CWE-613 | Critical9.8 | — | 1.2% | Aug 14, 2020 |
39Monitor | CVE-2015-5171No exploit | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Critical9.8 | — | 1.2% | Oct 24, 2017 |
- CVE-2014-259544Plan
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication
CriticalCVSS 9.8Proof of conceptEPSS 17%barracuda · web application firewallFeb 11, 2020
- CVE-2020-2742241Plan
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s
CriticalCVSS 9.8Proof of conceptEPSS 8%anuko · time trackerNov 16, 2020
- CVE-2021-2401940Plan
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke
CriticalCVSS 9.8Proof of conceptEPSS 4%fortinet · forticlient endpoint management serverOct 6, 2021
- CVE-2020-823440Plan
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
CriticalCVSS 9.8No exploitEPSS 3%ui · edgemax firmwareAug 21, 2020
- CVE-2020-2966740Plan
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca
CriticalCVSS 9.8Proof of conceptEPSS 3%lanatmservice · m3 atm monitoring systemDec 10, 2020
- CVE-2016-654540Plan
iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request
CriticalCVSS 9.8No exploitEPSS 3%ieasytec · itrackeasyJul 13, 2018
- CVE-2021-331140Plan
An issue was discovered in October through build 471.
CriticalCVSS 9.8No exploitEPSS 3%octobercms · octoberFeb 5, 2021
- CVE-2018-2101840Plan
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
CriticalCVSS 9.8No exploitEPSS 3%joinmastodon · mastodonSep 22, 2019
- CVE-2016-1101440Plan
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
CriticalCVSS 9.8No exploitEPSS 3%netgear · jnr1010 firmwareOct 16, 2019
- CVE-2021-2598140Plan
Talkyard - Insufficient Session Expiration
CriticalCVSS 9.8No exploitEPSS 2%talkyard · talkyardJan 3, 2022
- CVE-2020-3535840Plan
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%domainmod · domainmodMar 15, 2021
- CVE-2019-814940Plan
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
CriticalCVSS 9.8No exploitEPSS 2%magento · magentoNov 5, 2019
- CVE-2020-2773940Plan
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u
CriticalCVSS 9.8No exploitEPSS 2%citadel · webcitOct 28, 2020
- CVE-2020-2741639Monitor
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c
CriticalCVSS 9.8No exploitEPSS 2%mahadiscom · mahavitaranDec 8, 2021
- CVE-2021-2599239Monitor
ifme - Insufficient Session Expiration
CriticalCVSS 9.8No exploitEPSS 2%if-me · ifmeFeb 10, 2022
- CVE-2020-664939Monitor
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex
CriticalCVSS 9.8No exploitEPSS 2%fortinet · fortiisolatorFeb 8, 2021
- CVE-2021-3882339Monitor
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.
CriticalCVSS 9.8No exploitEPSS 2%icehrm · icehrmOct 4, 2021
- CVE-2021-3733339Monitor
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.
CriticalCVSS 9.8No exploitEPSS 1%bookingcore · booking coreOct 4, 2021
- CVE-2018-663439Monitor
A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access
CriticalCVSS 9.8No exploitEPSS 1%parsecgaming · parsecMay 7, 2019
- CVE-2016-506939Monitor
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
CriticalCVSS 9.8No exploitEPSS 1%sierrawireless · aleos firmwareApr 9, 2017
- CVE-2021-4084939Monitor
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a
CriticalCVSS 9.8No exploitEPSS 1%mahara · maharaNov 3, 2021
- CVE-2022-271339Monitor
Insufficient Session Expiration in cockpit-hq/cockpit
CriticalCVSS 9.8No exploitEPSS 1%agentejo · cockpitAug 8, 2022
- CVE-2021-3633039Monitor
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.
CriticalCVSS 9.8No exploitEPSS 1%dell · emc streaming data platformNov 30, 2021
- CVE-2020-1747439Monitor
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne
CriticalCVSS 9.8No exploitEPSS 1%zkteco · zkbiosecurity serverAug 14, 2020
- CVE-2015-517139Monitor
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-releaseOct 24, 2017