Перейти к содержимому
Noroxi

CWE-384 · 417 записей

Session Fixation

CVE этого класса

417 записей

  • CVE-2018-11714
    59В плане

    An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0

    КритическаяCVSS 9,8Proof of conceptEPSS 68 %

    tp-link · tl-wr840n firmware4 июн. 2018 г.

  • CVE-2018-18925
    48В плане

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    КритическаяCVSS 9,8Proof of conceptEPSS 31 %

    gogs · gogs4 нояб. 2018 г.

  • CVE-2017-12965
    44В плане

    Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.

    КритическаяCVSS 9,8Proof of conceptEPSS 16 %

    apache2triad · apache2triad23 авг. 2017 г.

  • CVE-2025-52689
    43В плане

    Weak Session ID Check in the OmniAccess Stellar Web Management Interface

    КритическаяCVSS 9,8Proof of conceptEPSS 14 %

    alcatel-lucent · omniaccess stellar products16 июл. 2025 г.

  • CVE-2019-10008
    41В плане

    Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co

    ВысокаяCVSS 8,8Proof of conceptEPSS 19 %

    zohocorp · servicedesk plus24 апр. 2019 г.

  • CVE-2021-36394
    41В плане

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

    КритическаяCVSS 9,8Proof of conceptEPSS 7 %

    moodle · moodle6 мар. 2023 г.

  • CVE-2015-1820
    40В плане

    REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    rest-client project · rest-client9 авг. 2017 г.

  • CVE-2019-18418
    40В плане

    clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    clonos · clonos24 окт. 2019 г.

  • CVE-2019-5523
    40В плане

    VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    vmware · vcloud director1 апр. 2019 г.

  • CVE-2018-18926
    40В плане

    Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    gitea · gitea4 нояб. 2018 г.

  • CVE-2015-1174
    40В плане

    Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    unit4 · teta web2 авг. 2017 г.

  • CVE-2016-9125
    40В плане

    Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    revive-adserver · revive adserver27 мар. 2017 г.

  • CVE-2020-5543
    40В плане

    TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mitsubishielectric · iu1-1m20-d firmware15 мар. 2020 г.

  • CVE-2022-38054
    40В плане

    In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    apache · airflow2 сент. 2022 г.

  • CVE-2017-12868
    40В плане

    The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    simplesamlphp · simplesamlphp1 сент. 2017 г.

  • CVE-2023-31498
    40В плане

    A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    phpgurukul · hospital management system11 мая 2023 г.

  • CVE-2018-6959
    40В плане

    VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    vmware · vrealize automation13 апр. 2018 г.

  • CVE-2019-10158
    40В плане

    A flaw was found in Infinispan through version 9.4.14.Final.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    infinispan · infinispan2 янв. 2020 г.

  • CVE-2016-10405
    40В плане

    Session fixation vulnerability in D-Link DIR-600L routers (rev.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    d-link · dir-600l firmware7 сент. 2017 г.

  • CVE-2020-11729
    40В плане

    An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    davical · andrew\'s web libraries15 апр. 2020 г.

  • CVE-2025-28242
    40В плане

    Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.

    КритическаяCVSS 9,8Proof of conceptEPSS 2 %

    18 апр. 2025 г.

  • CVE-2021-20151
    40В плане

    Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    trendnet · tew-827dru firmware30 дек. 2021 г.

  • CVE-2017-12873
    39Наблюдать

    SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    simplesamlphp · simplesamlphp1 сент. 2017 г.

  • CVE-2023-41012
    39Наблюдать

    An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    chinamobile · intelligent home gateway firmware5 сент. 2023 г.

  • CVE-2021-39290
    39Наблюдать

    Certain NetModule devices allow Limited Session Fixation via PHPSESSID.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    netmodule · netmodule router software23 авг. 2021 г.

Все классы уязвимостей