Skip to content
Noroxi

CWE-613 · 608 records

Insufficient Session Expiration

CVEs in this class

608 records

  • Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication

    CriticalCVSS 9.8Proof of conceptEPSS 17%

    barracuda · web application firewallFeb 11, 2020

  • In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s

    CriticalCVSS 9.8Proof of conceptEPSS 8%

    anuko · time trackerNov 16, 2020

  • An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke

    CriticalCVSS 9.8Proof of conceptEPSS 4%

    fortinet · forticlient endpoint management serverOct 6, 2021

  • A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g

    CriticalCVSS 9.8No exploitEPSS 3%

    ui · edgemax firmwareAug 21, 2020

  • In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    lanatmservice · m3 atm monitoring systemDec 10, 2020

  • iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request

    CriticalCVSS 9.8No exploitEPSS 3%

    ieasytec · itrackeasyJul 13, 2018

  • An issue was discovered in October through build 471.

    CriticalCVSS 9.8No exploitEPSS 3%

    octobercms · octoberFeb 5, 2021

  • Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

    CriticalCVSS 9.8No exploitEPSS 3%

    joinmastodon · mastodonSep 22, 2019

  • NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

    CriticalCVSS 9.8No exploitEPSS 3%

    netgear · jnr1010 firmwareOct 16, 2019

  • Talkyard - Insufficient Session Expiration

    CriticalCVSS 9.8No exploitEPSS 2%

    talkyard · talkyardJan 3, 2022

  • DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.

    CriticalCVSS 9.8No exploitEPSS 2%

    domainmod · domainmodMar 15, 2021

  • Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    CriticalCVSS 9.8No exploitEPSS 2%

    magento · magentoNov 5, 2019

  • A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u

    CriticalCVSS 9.8No exploitEPSS 2%

    citadel · webcitOct 28, 2020

  • Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c

    CriticalCVSS 9.8No exploitEPSS 2%

    mahadiscom · mahavitaranDec 8, 2021

  • ifme - Insufficient Session Expiration

    CriticalCVSS 9.8No exploitEPSS 2%

    if-me · ifmeFeb 10, 2022

  • CVE-2020-6649
    39Monitor

    An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex

    CriticalCVSS 9.8No exploitEPSS 2%

    fortinet · fortiisolatorFeb 8, 2021

  • The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.

    CriticalCVSS 9.8No exploitEPSS 2%

    icehrm · icehrmOct 4, 2021

  • Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.

    CriticalCVSS 9.8No exploitEPSS 1%

    bookingcore · booking coreOct 4, 2021

  • CVE-2018-6634
    39Monitor

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access

    CriticalCVSS 9.8No exploitEPSS 1%

    parsecgaming · parsecMay 7, 2019

  • CVE-2016-5069
    39Monitor

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

    CriticalCVSS 9.8No exploitEPSS 1%

    sierrawireless · aleos firmwareApr 9, 2017

  • In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a

    CriticalCVSS 9.8No exploitEPSS 1%

    mahara · maharaNov 3, 2021

  • CVE-2022-2713
    39Monitor

    Insufficient Session Expiration in cockpit-hq/cockpit

    CriticalCVSS 9.8No exploitEPSS 1%

    agentejo · cockpitAug 8, 2022

  • Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.

    CriticalCVSS 9.8No exploitEPSS 1%

    dell · emc streaming data platformNov 30, 2021

  • A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne

    CriticalCVSS 9.8No exploitEPSS 1%

    zkteco · zkbiosecurity serverAug 14, 2020

  • CVE-2015-5171
    39Monitor

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic

    CriticalCVSS 9.8No exploitEPSS 1%

    cloudfoundry · cf-releaseOct 24, 2017

All vulnerability classes