CWE-324 · 25 kayıt
Use of a Key Past its Expiration Date
Bu sınıftaki CVE’ler
25 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2024-36031İstismar yok | keys: Fix overwrite of key expiration on instantiationlinux · linux kernel · CWE-324 | Kritik9,8 | — | %0,7 | 30 May 2024 |
39İzleyin | CVE-2025-2291İstismar yok | PgBouncer default auth_query does not take Postgres password expiry into accountpgbouncer · pgbouncer · CWE-324 | Kritik9,8 | — | %0,4 | 16 Nis 2025 |
38İzleyin | CVE-2022-35401İstismar yok | An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230.asus · rt-ax82u firmware · CWE-324 | Yüksek8,1 | — | %20,8 | 10 Oca 2023 |
36İzleyin | CVE-2026-39923İstismar yok | Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /resetflarum · flarum framework · CWE-324 | Kritik9,2 | — | %0,4 | 5 Ağu 2026 |
35İzleyin | CVE-2022-24732İstismar yok | Maddy Mail Server does not implement account expirymaddy project · maddy · CWE-324 | Yüksek8,8 | — | %0,4 | 9 Mar 2022 |
35İzleyin | CVE-2025-33012İstismar yok | IBM Db2 improper account lockoutibm · db2 · CWE-324 | Yüksek8,8 | — | %0,2 | 7 Kas 2025 |
34İzleyin | CVE-2025-31123İstismar yok | Zitadel Expired JWT Keys Usable for Authorization Grantszitadel · zitadel · CWE-324 | Yüksek8,7 | — | %0,4 | 31 Mar 2025 |
30İzleyin | CVE-2021-33020İstismar yok | Philips Vue PACS Use of a Key Past its Expiration Datephilips · myvue · CWE-324 | Yüksek7,5 | — | %0,6 | 1 Nis 2022 |
30İzleyin | CVE-2023-6960İstismar yok | TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.sciener · ttlock app · CWE-324 | Yüksek7,5 | — | %0,3 | 15 Mar 2024 |
30İzleyin | CVE-2025-13723İstismar yok | IBM Sterling Partner Engagement Manager Information Disclosureibm · sterling partner engagement manager · CWE-324 | Yüksek7,5 | — | %0,2 | 13 Mar 2026 |
27İzleyin | CVE-2026-52809İstismar yok | Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVESgogs · gogs · CWE-324 | Orta6,8 | — | %0,2 | 24 Haz 2026 |
26İzleyin | CVE-2022-2447İstismar yok | A flaw was found in Keystone.openstack · keystone · CWE-324 | Orta6,6 | — | %0,7 | 1 Eyl 2022 |
26İzleyin | CVE-2024-31895İstismar yok | IBM App Connect Enterprise information disclosureibm · app connect enterprise · CWE-324 | Orta6,5 | — | %0,3 | 22 May 2024 |
26İzleyin | CVE-2024-25679İstismar yok | In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by sepquic · pquic · CWE-324 | Orta6,5 | — | %0,3 | 9 Şub 2024 |
21İzleyin | CVE-2019-3790İstismar yok | Ops Manager uaa client issues tokens after refresh token expirationpivotal software · operations manager · CWE-324 | Orta5,4 | — | %0,7 | 6 Haz 2019 |
21İzleyin | CVE-2024-38277İstismar yok | moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keysmoodle · moodle · CWE-324 | Orta5,4 | — | %0,2 | 18 Haz 2024 |
19İzleyin | CVE-2024-7318İstismar yok | Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverityredhat · build of keycloak · CWE-324 | Orta4,8 | — | %0,4 | 9 Eyl 2024 |
19İzleyin | GHSA-57rh-gr4v-j5f6İstismar yok | Duplicate Advisory: Keycloak Uses a Key Past its Expiration DateMaven · org.keycloak:keycloak-core · CWE-324 | Orta4,8 | — | — | 9 Eyl 2024 |
18İzleyin | CVE-2025-48813İstismar yok | Virtual Secure Mode Spoofing Vulnerabilitymicrosoft · windows 10 1809 · CWE-324 | Orta4,7 | — | %0,3 | 14 Eki 2025 |
17İzleyin | CVE-2024-31894İstismar yok | IBM App Connect Enterprise information disclosureibm · app connect enterprise · CWE-324 | Orta4,3 | — | %0,3 | 22 May 2024 |
17İzleyin | CVE-2024-31893İstismar yok | IBM App Connect Enterprise information disclosureibm · app connect enterprise · CWE-324 | Orta4,3 | — | %0,3 | 22 May 2024 |
16İzleyin | CVE-2023-5342İstismar yok | Shim: expired secure boot certificatered hat · red hat enterprise linux 10 · CWE-324 | Orta4,1 | — | %0,1 | 14 Ağu 2025 |
14İzleyin | CVE-2024-6299İstismar yok | Use of a Key Past its Expiration Date in Conduitconduit · conduit · CWE-324 | Düşük3,7 | — | %0,2 | 25 Haz 2024 |
12İzleyin | CVE-2026-54787İstismar yok | sigstore-go fails to check signature timestamps against a signing key's validity periodsigstore · sigstore-go · CWE-324 | Düşük3,1 | — | %0,1 | 31 Tem 2026 |
10İzleyin | GHSA-3rw9-wmc8-8948İstismar yok | Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh tokenGo · github.com/coder/coder/v2 · CWE-324 | Düşük2,5 | — | — | 28 Ağu 2025 |
- CVE-2024-3603139İzleyin
keys: Fix overwrite of key expiration on instantiation
KritikCVSS 9,8İstismar yokEPSS %1linux · linux kernel30 May 2024
- CVE-2025-229139İzleyin
PgBouncer default auth_query does not take Postgres password expiry into account
KritikCVSS 9,8İstismar yokEPSS %0pgbouncer · pgbouncer16 Nis 2025
- CVE-2022-3540138İzleyin
An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230.
YüksekCVSS 8,1İstismar yokEPSS %21asus · rt-ax82u firmware10 Oca 2023
- CVE-2026-3992336İzleyin
Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
KritikCVSS 9,2İstismar yokEPSS %0flarum · flarum framework5 Ağu 2026
- CVE-2022-2473235İzleyin
Maddy Mail Server does not implement account expiry
YüksekCVSS 8,8İstismar yokEPSS %0maddy project · maddy9 Mar 2022
- CVE-2025-3301235İzleyin
IBM Db2 improper account lockout
YüksekCVSS 8,8İstismar yokEPSS %0ibm · db27 Kas 2025
- CVE-2025-3112334İzleyin
Zitadel Expired JWT Keys Usable for Authorization Grants
YüksekCVSS 8,7İstismar yokEPSS %0zitadel · zitadel31 Mar 2025
- CVE-2021-3302030İzleyin
Philips Vue PACS Use of a Key Past its Expiration Date
YüksekCVSS 7,5İstismar yokEPSS %1philips · myvue1 Nis 2022
- CVE-2023-696030İzleyin
TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.
YüksekCVSS 7,5İstismar yokEPSS %0sciener · ttlock app15 Mar 2024
- CVE-2025-1372330İzleyin
IBM Sterling Partner Engagement Manager Information Disclosure
YüksekCVSS 7,5İstismar yokEPSS %0ibm · sterling partner engagement manager13 Mar 2026
- CVE-2026-5280927İzleyin
Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
OrtaCVSS 6,8İstismar yokEPSS %0gogs · gogs24 Haz 2026
- CVE-2022-244726İzleyin
A flaw was found in Keystone.
OrtaCVSS 6,6İstismar yokEPSS %1openstack · keystone1 Eyl 2022
- CVE-2024-3189526İzleyin
IBM App Connect Enterprise information disclosure
OrtaCVSS 6,5İstismar yokEPSS %0ibm · app connect enterprise22 May 2024
- CVE-2024-2567926İzleyin
In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by se
OrtaCVSS 6,5İstismar yokEPSS %0pquic · pquic9 Şub 2024
- CVE-2019-379021İzleyin
Ops Manager uaa client issues tokens after refresh token expiration
OrtaCVSS 5,4İstismar yokEPSS %1pivotal software · operations manager6 Haz 2019
- CVE-2024-3827721İzleyin
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
OrtaCVSS 5,4İstismar yokEPSS %0moodle · moodle18 Haz 2024
- CVE-2024-731819İzleyin
Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity
OrtaCVSS 4,8İstismar yokEPSS %0redhat · build of keycloak9 Eyl 2024
- GHSA-57rh-gr4v-j5f619İzleyin
Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date
OrtaCVSS 4,8İstismar yokMaven · org.keycloak:keycloak-core9 Eyl 2024
- CVE-2025-4881318İzleyin
Virtual Secure Mode Spoofing Vulnerability
OrtaCVSS 4,7İstismar yokEPSS %0microsoft · windows 10 180914 Eki 2025
- CVE-2024-3189417İzleyin
IBM App Connect Enterprise information disclosure
OrtaCVSS 4,3İstismar yokEPSS %0ibm · app connect enterprise22 May 2024
- CVE-2024-3189317İzleyin
IBM App Connect Enterprise information disclosure
OrtaCVSS 4,3İstismar yokEPSS %0ibm · app connect enterprise22 May 2024
- CVE-2023-534216İzleyin
Shim: expired secure boot certificate
OrtaCVSS 4,1İstismar yokEPSS %0red hat · red hat enterprise linux 1014 Ağu 2025
- CVE-2024-629914İzleyin
Use of a Key Past its Expiration Date in Conduit
DüşükCVSS 3,7İstismar yokEPSS %0conduit · conduit25 Haz 2024
- CVE-2026-5478712İzleyin
sigstore-go fails to check signature timestamps against a signing key's validity period
DüşükCVSS 3,1İstismar yokEPSS %0sigstore · sigstore-go31 Tem 2026
- GHSA-3rw9-wmc8-894810İzleyin
Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token
DüşükCVSS 2,5İstismar yokGo · github.com/coder/coder/v228 Ağu 2025