Перейти к содержимому
Noroxi

CWE-613 · 596 записей

Insufficient Session Expiration

CVE этого класса

597 записей

  • CVE-2014-2595
    44В плане

    Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication

    КритическаяCVSS 9,8Proof of conceptEPSS 17 %

    barracuda · web application firewall11 февр. 2020 г.

  • CVE-2020-27422
    41В плане

    In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s

    КритическаяCVSS 9,8Proof of conceptEPSS 8 %

    anuko · time tracker16 нояб. 2020 г.

  • CVE-2021-24019
    40В плане

    An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke

    КритическаяCVSS 9,8Proof of conceptEPSS 4 %

    fortinet · forticlient endpoint management server6 окт. 2021 г.

  • CVE-2020-8234
    40В плане

    A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ui · edgemax firmware21 авг. 2020 г.

  • CVE-2020-29667
    40В плане

    In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    lanatmservice · m3 atm monitoring system10 дек. 2020 г.

  • CVE-2016-6545
    40В плане

    iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    ieasytec · itrackeasy13 июл. 2018 г.

  • CVE-2021-3311
    40В плане

    An issue was discovered in October through build 471.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    octobercms · october5 февр. 2021 г.

  • CVE-2018-21018
    40В плане

    Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    joinmastodon · mastodon22 сент. 2019 г.

  • CVE-2016-11014
    40В плане

    NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    netgear · jnr1010 firmware16 окт. 2019 г.

  • CVE-2021-25981
    40В плане

    Talkyard - Insufficient Session Expiration

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    talkyard · talkyard3 янв. 2022 г.

  • CVE-2020-35358
    40В плане

    DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    domainmod · domainmod15 мар. 2021 г.

  • CVE-2019-8149
    40В плане

    Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    magento · magento5 нояб. 2019 г.

  • CVE-2020-27739
    40В плане

    A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    citadel · webcit28 окт. 2020 г.

  • CVE-2021-25992
    39Наблюдать

    ifme - Insufficient Session Expiration

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    if-me · ifme10 февр. 2022 г.

  • CVE-2020-27416
    39Наблюдать

    Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mahadiscom · mahavitaran8 дек. 2021 г.

  • CVE-2020-6649
    39Наблюдать

    An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    fortinet · fortiisolator8 февр. 2021 г.

  • CVE-2021-38823
    39Наблюдать

    The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    icehrm · icehrm4 окт. 2021 г.

  • CVE-2021-37333
    39Наблюдать

    Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    bookingcore · booking core4 окт. 2021 г.

  • CVE-2018-6634
    39Наблюдать

    A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    parsecgaming · parsec7 мая 2019 г.

  • CVE-2016-5069
    39Наблюдать

    Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    sierrawireless · aleos firmware9 апр. 2017 г.

  • CVE-2021-40849
    39Наблюдать

    In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    mahara · mahara3 нояб. 2021 г.

  • CVE-2022-2713
    39Наблюдать

    Insufficient Session Expiration in cockpit-hq/cockpit

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    agentejo · cockpit8 авг. 2022 г.

  • CVE-2021-36330
    39Наблюдать

    Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    dell · emc streaming data platform30 нояб. 2021 г.

  • CVE-2020-17474
    39Наблюдать

    A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    zkteco · zkbiosecurity server14 авг. 2020 г.

  • CVE-2015-5171
    39Наблюдать

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release24 окт. 2017 г.

Все классы уязвимостей