Перейти к содержимому
Noroxi

CWE-488 · 37 записей

Exposure of Data Element to Wrong Session

CVE этого класса

37 записей

  • CVE-2024-38367
    41В плане

    CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking

    КритическаяCVSS 9,6Эксплойта нетEPSS 11 %

    cocoapods · trunk.cocoapods.org1 июл. 2024 г.

  • CVE-2026-16326
    40В плане

    consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    hashicorp · tooling29 июл. 2026 г.

  • CVE-2026-16498
    40В плане

    terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    КритическаяCVSS 10,0Эксплойта нетEPSS 0 %

    hashicorp · tooling28 июл. 2026 г.

  • CVE-2026-19931
    39Наблюдать

    Negotiate ambient user conn reuse

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    haxx · curl6 сент. 2026 г.

  • CVE-2024-27455
    36Наблюдать

    In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    26 февр. 2024 г.

  • CVE-2025-47928
    36Наблюдать

    Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`

    КритическаяCVSS 9,1Proof of conceptEPSS 1 %

    spotipy-dev · spotipy15 мая 2025 г.

  • CVE-2026-86492
    34Наблюдать

    In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

    ВысокаяCVSS 8,5Эксплойта нетEPSS 1 %

    jetbrains · youtrack7 сент. 2026 г.

  • CVE-2025-1247
    33Наблюдать

    Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    red hat · red hat build of apache camel 4.8 for quarkus 3.1513 февр. 2025 г.

  • CVE-2024-27935
    33Наблюдать

    Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination

    ВысокаяCVSS 8,3Эксплойта нетEPSS 1 %

    deno · deno20 мар. 2024 г.

  • GHSA-82vp-jr39-4j2j
    32Наблюдать

    TYPO3 Security Misconfiguration in Frontend Session Handling

    ВысокаяCVSS 8,2Эксплойта нет

    Packagist · typo3/cms-core30 мая 2024 г.

  • CVE-2024-6162
    31Наблюдать

    Undertow: url-encoded request path information can be broken on ajp-listener

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    red hat · eap 8.0.120 июн. 2024 г.

  • CVE-2022-40210
    31Наблюдать

    Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enab

    ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %

    intel · data center manager10 мая 2023 г.

  • CVE-2026-80231
    30Наблюдать

    native CA store conn reuse

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    haxx · curl6 сент. 2026 г.

  • CVE-2026-5773
    30Наблюдать

    wrong reuse of SMB connection

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    haxx · curl13 мая 2026 г.

  • CVE-2024-5148
    30Наблюдать

    Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    red hat · red hat enterprise linux 102 сент. 2024 г.

  • CVE-2023-6519
    30Наблюдать

    Seeing admin password hash value in Mia Technology's Mia-Med

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    miateknoloji · mia-med8 февр. 2024 г.

  • CVE-2023-1907
    30Наблюдать

    Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    pgadmin · pgadmin9 янв. 2025 г.

  • CVE-2025-30073
    30Наблюдать

    An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    26 мар. 2025 г.

  • CVE-2024-41977
    29Наблюдать

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    siemens · ruggedcom rm1224 lte\(4g\) eu firmware13 авг. 2024 г.

  • CVE-2026-88017
    29Наблюдать

    rclone: FTP cross-session auth-proxy backend confusion

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    rclone · rclone10 сент. 2026 г.

  • CVE-2026-18489
    29Наблюдать

    IBM ContextForge Translate is affected by cross-client credential context confusion

    ВысокаяCVSS 7,4Эксплойта нетEPSS 0 %

    ibm · contextforge4 сент. 2026 г.

  • CVE-2026-23919
    28Наблюдать

    Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    zabbix · zabbix24 мар. 2026 г.

  • CVE-2026-8458
    26Наблюдать

    wrong reuse for different services

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    haxx · curl3 июл. 2026 г.

  • CVE-2026-23646
    26Наблюдать

    OpenProject users can delete other user's session, causing them to be logged out

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    openproject · openproject19 янв. 2026 г.

  • CVE-2026-84685
    26Наблюдать

    Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    auth0 · react-native-auth08 сент. 2026 г.

Все классы уязвимостей