İçeriğe atla
Noroxi

CWE-324 · 25 kayıt

Use of a Key Past its Expiration Date

Bu sınıftaki CVE’ler

25 kayıt

  • CVE-2024-36031
    39İzleyin

    keys: Fix overwrite of key expiration on instantiation

    KritikCVSS 9,8İstismar yokEPSS %1

    linux · linux kernel30 May 2024

  • CVE-2025-2291
    39İzleyin

    PgBouncer default auth_query does not take Postgres password expiry into account

    KritikCVSS 9,8İstismar yokEPSS %0

    pgbouncer · pgbouncer16 Nis 2025

  • CVE-2022-35401
    38İzleyin

    An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230.

    YüksekCVSS 8,1İstismar yokEPSS %21

    asus · rt-ax82u firmware10 Oca 2023

  • CVE-2026-39923
    36İzleyin

    Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset

    KritikCVSS 9,2İstismar yokEPSS %0

    flarum · flarum framework5 Ağu 2026

  • CVE-2022-24732
    35İzleyin

    Maddy Mail Server does not implement account expiry

    YüksekCVSS 8,8İstismar yokEPSS %0

    maddy project · maddy9 Mar 2022

  • CVE-2025-33012
    35İzleyin

    IBM Db2 improper account lockout

    YüksekCVSS 8,8İstismar yokEPSS %0

    ibm · db27 Kas 2025

  • CVE-2025-31123
    34İzleyin

    Zitadel Expired JWT Keys Usable for Authorization Grants

    YüksekCVSS 8,7İstismar yokEPSS %0

    zitadel · zitadel31 Mar 2025

  • CVE-2021-33020
    30İzleyin

    Philips Vue PACS Use of a Key Past its Expiration Date

    YüksekCVSS 7,5İstismar yokEPSS %1

    philips · myvue1 Nis 2022

  • CVE-2023-6960
    30İzleyin

    TTLock App virtual keys and settings are only deleted client side, and if preserved, can access the lock after intended deletion.

    YüksekCVSS 7,5İstismar yokEPSS %0

    sciener · ttlock app15 Mar 2024

  • CVE-2025-13723
    30İzleyin

    IBM Sterling Partner Engagement Manager Information Disclosure

    YüksekCVSS 7,5İstismar yokEPSS %0

    ibm · sterling partner engagement manager13 Mar 2026

  • CVE-2026-52809
    27İzleyin

    Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES

    OrtaCVSS 6,8İstismar yokEPSS %0

    gogs · gogs24 Haz 2026

  • CVE-2022-2447
    26İzleyin

    A flaw was found in Keystone.

    OrtaCVSS 6,6İstismar yokEPSS %1

    openstack · keystone1 Eyl 2022

  • CVE-2024-31895
    26İzleyin

    IBM App Connect Enterprise information disclosure

    OrtaCVSS 6,5İstismar yokEPSS %0

    ibm · app connect enterprise22 May 2024

  • CVE-2024-25679
    26İzleyin

    In PQUIC before 5bde5bb, retention of unused initial encryption keys allows attackers to disrupt a connection with a PSK configuration by se

    OrtaCVSS 6,5İstismar yokEPSS %0

    pquic · pquic9 Şub 2024

  • CVE-2019-3790
    21İzleyin

    Ops Manager uaa client issues tokens after refresh token expiration

    OrtaCVSS 5,4İstismar yokEPSS %1

    pivotal software · operations manager6 Haz 2019

  • CVE-2024-38277
    21İzleyin

    moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys

    OrtaCVSS 5,4İstismar yokEPSS %0

    moodle · moodle18 Haz 2024

  • CVE-2024-7318
    19İzleyin

    Keycloak-core: one time passcode (otp) is valid longer than expiration timeseverity

    OrtaCVSS 4,8İstismar yokEPSS %0

    redhat · build of keycloak9 Eyl 2024

  • Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date

    OrtaCVSS 4,8İstismar yok

    Maven · org.keycloak:keycloak-core9 Eyl 2024

  • CVE-2025-48813
    18İzleyin

    Virtual Secure Mode Spoofing Vulnerability

    OrtaCVSS 4,7İstismar yokEPSS %0

    microsoft · windows 10 180914 Eki 2025

  • CVE-2024-31894
    17İzleyin

    IBM App Connect Enterprise information disclosure

    OrtaCVSS 4,3İstismar yokEPSS %0

    ibm · app connect enterprise22 May 2024

  • CVE-2024-31893
    17İzleyin

    IBM App Connect Enterprise information disclosure

    OrtaCVSS 4,3İstismar yokEPSS %0

    ibm · app connect enterprise22 May 2024

  • CVE-2023-5342
    16İzleyin

    Shim: expired secure boot certificate

    OrtaCVSS 4,1İstismar yokEPSS %0

    red hat · red hat enterprise linux 1014 Ağu 2025

  • CVE-2024-6299
    14İzleyin

    Use of a Key Past its Expiration Date in Conduit

    DüşükCVSS 3,7İstismar yokEPSS %0

    conduit · conduit25 Haz 2024

  • CVE-2026-54787
    12İzleyin

    sigstore-go fails to check signature timestamps against a signing key's validity period

    DüşükCVSS 3,1İstismar yokEPSS %0

    sigstore · sigstore-go31 Tem 2026

  • Coder accepts an APIKey beyond the linked OIDC expiry if there is no refresh token

    DüşükCVSS 2,5İstismar yok

    Go · github.com/coder/coder/v228 Ağu 2025

Tüm zafiyet sınıfları