CWE-384 · 417 записей
Session Fixation
CVE этого класса
417 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
59В плане | CVE-2018-11714Proof of concept | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Критическая9,8 | — | 68,1 % | 4 июн. 2018 г. |
48В плане | CVE-2018-18925Proof of concept | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Критическая9,8 | — | 31,1 % | 4 нояб. 2018 г. |
44В плане | CVE-2017-12965Proof of concept | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.apache2triad · apache2triad · CWE-384 | Критическая9,8 | — | 15,7 % | 23 авг. 2017 г. |
43В плане | CVE-2025-52689Proof of concept | Weak Session ID Check in the OmniAccess Stellar Web Management Interfacealcatel-lucent · omniaccess stellar products · CWE-384 | Критическая9,8 | — | 13,5 % | 16 июл. 2025 г. |
41В плане | CVE-2019-10008Proof of concept | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically cozohocorp · servicedesk plus · CWE-384 | Высокая8,8 | — | 19,4 % | 24 апр. 2019 г. |
41В плане | CVE-2021-36394Proof of concept | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.moodle · moodle · CWE-384 | Критическая9,8 | — | 7,0 % | 6 мар. 2023 г. |
40В плане | CVE-2015-1820Эксплойта нет | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie irest-client project · rest-client · CWE-384 | Критическая9,8 | — | 4,3 % | 9 авг. 2017 г. |
40В плане | CVE-2019-18418Proof of concept | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no seclonos · clonos · CWE-384 | Критическая9,8 | — | 4,0 % | 24 окт. 2019 г. |
40В плане | CVE-2019-5523Эксплойта нет | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and vmware · vcloud director · CWE-384 | Критическая9,8 | — | 3,3 % | 1 апр. 2019 г. |
40В плане | CVE-2018-18926Эксплойта нет | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.gitea · gitea · CWE-384 | Критическая9,8 | — | 3,0 % | 4 нояб. 2018 г. |
40В плане | CVE-2015-1174Эксплойта нет | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack weunit4 · teta web · CWE-384 | Критическая9,8 | — | 2,9 % | 2 авг. 2017 г. |
40В плане | CVE-2016-9125Эксплойта нет | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, byrevive-adserver · revive adserver · CWE-384 | Критическая9,8 | — | 2,7 % | 27 мар. 2017 г. |
40В плане | CVE-2020-5543Эксплойта нет | TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not propermitsubishielectric · iu1-1m20-d firmware · CWE-384 | Критическая9,8 | — | 2,2 % | 15 мар. 2020 г. |
40В плане | CVE-2022-38054Эксплойта нет | In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.apache · airflow · CWE-384 | Критическая9,8 | — | 2,1 % | 2 сент. 2022 г. |
40В плане | CVE-2017-12868Эксплойта нет | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attasimplesamlphp · simplesamlphp · CWE-384 | Критическая9,8 | — | 2,1 % | 1 сент. 2017 г. |
40В плане | CVE-2023-31498Эксплойта нет | A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary codephpgurukul · hospital management system · CWE-384 | Критическая9,8 | — | 2,1 % | 11 мая 2023 г. |
40В плане | CVE-2018-6959Эксплойта нет | VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.vmware · vrealize automation · CWE-384 | Критическая9,8 | — | 2,0 % | 13 апр. 2018 г. |
40В плане | CVE-2019-10158Эксплойта нет | A flaw was found in Infinispan through version 9.4.14.Final.infinispan · infinispan · CWE-384 | Критическая9,8 | — | 2,0 % | 2 янв. 2020 г. |
40В плане | CVE-2016-10405Эксплойта нет | Session fixation vulnerability in D-Link DIR-600L routers (rev.d-link · dir-600l firmware · CWE-384 | Критическая9,8 | — | 1,9 % | 7 сент. 2017 г. |
40В плане | CVE-2020-11729Эксплойта нет | An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.davical · andrew\'s web libraries · CWE-384 | Критическая9,8 | — | 1,9 % | 15 апр. 2020 г. |
40В плане | CVE-2025-28242Proof of concept | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.CWE-384 | Критическая9,8 | — | 1,8 % | 18 апр. 2025 г. |
40В плане | CVE-2021-20151Эксплойта нет | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.trendnet · tew-827dru firmware · CWE-384 | Критическая10,0 | — | 1,6 % | 30 дек. 2021 г. |
39Наблюдать | CVE-2017-12873Эксплойта нет | SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified othsimplesamlphp · simplesamlphp · CWE-384 | Критическая9,8 | — | 1,7 % | 1 сент. 2017 г. |
39Наблюдать | CVE-2023-41012Эксплойта нет | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code chinamobile · intelligent home gateway firmware · CWE-384 | Критическая9,8 | — | 1,5 % | 5 сент. 2023 г. |
39Наблюдать | CVE-2021-39290Эксплойта нет | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Критическая9,8 | — | 1,5 % | 23 авг. 2021 г. |
- CVE-2018-1171459В плане
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
КритическаяCVSS 9,8Proof of conceptEPSS 68 %tp-link · tl-wr840n firmware4 июн. 2018 г.
- CVE-2018-1892548В плане
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
КритическаяCVSS 9,8Proof of conceptEPSS 31 %gogs · gogs4 нояб. 2018 г.
- CVE-2017-1296544В плане
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
КритическаяCVSS 9,8Proof of conceptEPSS 16 %apache2triad · apache2triad23 авг. 2017 г.
- CVE-2025-5268943В плане
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
КритическаяCVSS 9,8Proof of conceptEPSS 14 %alcatel-lucent · omniaccess stellar products16 июл. 2025 г.
- CVE-2019-1000841В плане
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co
ВысокаяCVSS 8,8Proof of conceptEPSS 19 %zohocorp · servicedesk plus24 апр. 2019 г.
- CVE-2021-3639441В плане
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
КритическаяCVSS 9,8Proof of conceptEPSS 7 %moodle · moodle6 мар. 2023 г.
- CVE-2015-182040В плане
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %rest-client project · rest-client9 авг. 2017 г.
- CVE-2019-1841840В плане
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se
КритическаяCVSS 9,8Proof of conceptEPSS 4 %clonos · clonos24 окт. 2019 г.
- CVE-2019-552340В плане
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %vmware · vcloud director1 апр. 2019 г.
- CVE-2018-1892640В плане
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %gitea · gitea4 нояб. 2018 г.
- CVE-2015-117440В плане
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %unit4 · teta web2 авг. 2017 г.
- CVE-2016-912540В плане
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %revive-adserver · revive adserver27 мар. 2017 г.
- CVE-2020-554340В плане
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mitsubishielectric · iu1-1m20-d firmware15 мар. 2020 г.
- CVE-2022-3805440В плане
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %apache · airflow2 сент. 2022 г.
- CVE-2017-1286840В плане
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2023-3149840В плане
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %phpgurukul · hospital management system11 мая 2023 г.
- CVE-2018-695940В плане
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %vmware · vrealize automation13 апр. 2018 г.
- CVE-2019-1015840В плане
A flaw was found in Infinispan through version 9.4.14.Final.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %infinispan · infinispan2 янв. 2020 г.
- CVE-2016-1040540В плане
Session fixation vulnerability in D-Link DIR-600L routers (rev.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %d-link · dir-600l firmware7 сент. 2017 г.
- CVE-2020-1172940В плане
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %davical · andrew\'s web libraries15 апр. 2020 г.
- CVE-2025-2824240В плане
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
КритическаяCVSS 9,8Proof of conceptEPSS 2 %18 апр. 2025 г.
- CVE-2021-2015140В плане
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %trendnet · tew-827dru firmware30 дек. 2021 г.
- CVE-2017-1287339Наблюдать
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %simplesamlphp · simplesamlphp1 сент. 2017 г.
- CVE-2023-4101239Наблюдать
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %chinamobile · intelligent home gateway firmware5 сент. 2023 г.
- CVE-2021-3929039Наблюдать
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %netmodule · netmodule router software23 авг. 2021 г.