CWE-384 · 417 kayıt
Session Fixation
Bu sınıftaki CVE’ler
417 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
59Planlayın | CVE-2018-11714Kavram kanıtı | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0tp-link · tl-wr840n firmware · CWE-384 | Kritik9,8 | — | %68,1 | 4 Haz 2018 |
48Planlayın | CVE-2018-18925Kavram kanıtı | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Kritik9,8 | — | %31,1 | 4 Kas 2018 |
44Planlayın | CVE-2017-12965Kavram kanıtı | Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.apache2triad · apache2triad · CWE-384 | Kritik9,8 | — | %15,7 | 23 Ağu 2017 |
43Planlayın | CVE-2025-52689Kavram kanıtı | Weak Session ID Check in the OmniAccess Stellar Web Management Interfacealcatel-lucent · omniaccess stellar products · CWE-384 | Kritik9,8 | — | %13,5 | 16 Tem 2025 |
41Planlayın | CVE-2019-10008Kavram kanıtı | Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically cozohocorp · servicedesk plus · CWE-384 | Yüksek8,8 | — | %19,4 | 24 Nis 2019 |
41Planlayın | CVE-2021-36394Kavram kanıtı | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.moodle · moodle · CWE-384 | Kritik9,8 | — | %7,0 | 6 Mar 2023 |
40Planlayın | CVE-2015-1820İstismar yok | REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie irest-client project · rest-client · CWE-384 | Kritik9,8 | — | %4,3 | 9 Ağu 2017 |
40Planlayın | CVE-2019-18418Kavram kanıtı | clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no seclonos · clonos · CWE-384 | Kritik9,8 | — | %4,0 | 24 Eki 2019 |
40Planlayın | CVE-2019-5523İstismar yok | VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and vmware · vcloud director · CWE-384 | Kritik9,8 | — | %3,3 | 1 Nis 2019 |
40Planlayın | CVE-2018-18926İstismar yok | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.gitea · gitea · CWE-384 | Kritik9,8 | — | %3,0 | 4 Kas 2018 |
40Planlayın | CVE-2015-1174İstismar yok | Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack weunit4 · teta web · CWE-384 | Kritik9,8 | — | %2,9 | 2 Ağu 2017 |
40Planlayın | CVE-2016-9125İstismar yok | Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, byrevive-adserver · revive adserver · CWE-384 | Kritik9,8 | — | %2,7 | 27 Mar 2017 |
40Planlayın | CVE-2020-5543İstismar yok | TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not propermitsubishielectric · iu1-1m20-d firmware · CWE-384 | Kritik9,8 | — | %2,2 | 15 Mar 2020 |
40Planlayın | CVE-2022-38054İstismar yok | In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.apache · airflow · CWE-384 | Kritik9,8 | — | %2,1 | 2 Eyl 2022 |
40Planlayın | CVE-2017-12868İstismar yok | The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows attasimplesamlphp · simplesamlphp · CWE-384 | Kritik9,8 | — | %2,1 | 1 Eyl 2017 |
40Planlayın | CVE-2023-31498İstismar yok | A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary codephpgurukul · hospital management system · CWE-384 | Kritik9,8 | — | %2,1 | 11 May 2023 |
40Planlayın | CVE-2018-6959İstismar yok | VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.vmware · vrealize automation · CWE-384 | Kritik9,8 | — | %2,0 | 13 Nis 2018 |
40Planlayın | CVE-2019-10158İstismar yok | A flaw was found in Infinispan through version 9.4.14.Final.infinispan · infinispan · CWE-384 | Kritik9,8 | — | %2,0 | 2 Oca 2020 |
40Planlayın | CVE-2016-10405İstismar yok | Session fixation vulnerability in D-Link DIR-600L routers (rev.d-link · dir-600l firmware · CWE-384 | Kritik9,8 | — | %1,9 | 7 Eyl 2017 |
40Planlayın | CVE-2020-11729İstismar yok | An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.davical · andrew\'s web libraries · CWE-384 | Kritik9,8 | — | %1,9 | 15 Nis 2020 |
40Planlayın | CVE-2025-28242Kavram kanıtı | Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.CWE-384 | Kritik9,8 | — | %1,8 | 18 Nis 2025 |
40Planlayın | CVE-2021-20151İstismar yok | Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.trendnet · tew-827dru firmware · CWE-384 | Kritik10,0 | — | %1,6 | 30 Ara 2021 |
39İzleyin | CVE-2017-12873İstismar yok | SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified othsimplesamlphp · simplesamlphp · CWE-384 | Kritik9,8 | — | %1,7 | 1 Eyl 2017 |
39İzleyin | CVE-2023-41012İstismar yok | An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code chinamobile · intelligent home gateway firmware · CWE-384 | Kritik9,8 | — | %1,5 | 5 Eyl 2023 |
39İzleyin | CVE-2021-39290İstismar yok | Certain NetModule devices allow Limited Session Fixation via PHPSESSID.netmodule · netmodule router software · CWE-384 | Kritik9,8 | — | %1,5 | 23 Ağu 2021 |
- CVE-2018-1171459Planlayın
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0
KritikCVSS 9,8Kavram kanıtıEPSS %68tp-link · tl-wr840n firmware4 Haz 2018
- CVE-2018-1892548Planlayın
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
KritikCVSS 9,8Kavram kanıtıEPSS %31gogs · gogs4 Kas 2018
- CVE-2017-1296544Planlayın
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %16apache2triad · apache2triad23 Ağu 2017
- CVE-2025-5268943Planlayın
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
KritikCVSS 9,8Kavram kanıtıEPSS %14alcatel-lucent · omniaccess stellar products16 Tem 2025
- CVE-2019-1000841Planlayın
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an established guest session is automatically co
YüksekCVSS 8,8Kavram kanıtıEPSS %19zohocorp · servicedesk plus24 Nis 2019
- CVE-2021-3639441Planlayın
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
KritikCVSS 9,8Kavram kanıtıEPSS %7moodle · moodle6 Mar 2023
- CVE-2015-182040Planlayın
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session fixation attacks or obtain sensitive cookie i
KritikCVSS 9,8İstismar yokEPSS %4rest-client project · rest-client9 Ağu 2017
- CVE-2019-1841840Planlayın
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests because there is no se
KritikCVSS 9,8Kavram kanıtıEPSS %4clonos · clonos24 Eki 2019
- CVE-2019-552340Planlayın
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Session Hijack vulnerability in the Tenant and
KritikCVSS 9,8İstismar yokEPSS %3vmware · vcloud director1 Nis 2019
- CVE-2018-1892640Planlayın
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
KritikCVSS 9,8İstismar yokEPSS %3gitea · gitea4 Kas 2018
- CVE-2015-117440Planlayın
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and earlier allows remote attackers to hijack we
KritikCVSS 9,8İstismar yokEPSS %3unit4 · teta web2 Ağu 2017
- CVE-2016-912540Planlayın
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by
KritikCVSS 9,8İstismar yokEPSS %3revive-adserver · revive adserver27 Mar 2017
- CVE-2020-554340Planlayın
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not proper
KritikCVSS 9,8İstismar yokEPSS %2mitsubishielectric · iu1-1m20-d firmware15 Mar 2020
- CVE-2022-3805440Planlayın
In Apache Airflow versions 2.2.4 through 2.3.3, the `database` webserver session backend was susceptible to session fixation.
KritikCVSS 9,8İstismar yokEPSS %2apache · airflow2 Eyl 2022
- CVE-2017-1286840Planlayın
The secureCompare method in lib/SimpleSAML/Utils/Crypto.php in SimpleSAMLphp 1.14.13 and earlier, when used with PHP before 5.6, allows atta
KritikCVSS 9,8İstismar yokEPSS %2simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2023-3149840Planlayın
A privilege escalation issue was found in PHP Gurukul Hospital Management System In v.4.0 allows a remote attacker to execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %2phpgurukul · hospital management system11 May 2023
- CVE-2018-695940Planlayın
VMware vRealize Automation (vRA) prior to 7.4.0 contains a vulnerability in the handling of session IDs.
KritikCVSS 9,8İstismar yokEPSS %2vmware · vrealize automation13 Nis 2018
- CVE-2019-1015840Planlayın
A flaw was found in Infinispan through version 9.4.14.Final.
KritikCVSS 9,8İstismar yokEPSS %2infinispan · infinispan2 Oca 2020
- CVE-2016-1040540Planlayın
Session fixation vulnerability in D-Link DIR-600L routers (rev.
KritikCVSS 9,8İstismar yokEPSS %2d-link · dir-600l firmware7 Eyl 2017
- CVE-2020-1172940Planlayın
An issue was discovered in DAViCal Andrew's Web Libraries (AWL) through 0.60.
KritikCVSS 9,8İstismar yokEPSS %2davical · andrew\'s web libraries15 Nis 2020
- CVE-2025-2824240Planlayın
Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows attackers to execute a session hijacking attack.
KritikCVSS 9,8Kavram kanıtıEPSS %218 Nis 2025
- CVE-2021-2015140Planlayın
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the device.
KritikCVSS 10,0İstismar yokEPSS %2trendnet · tew-827dru firmware30 Ara 2021
- CVE-2017-1287339İzleyin
SimpleSAMLphp 1.7.0 through 1.14.10 might allow attackers to obtain sensitive information, gain unauthorized access, or have unspecified oth
KritikCVSS 9,8İstismar yokEPSS %2simplesamlphp · simplesamlphp1 Eyl 2017
- CVE-2023-4101239İzleyin
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code
KritikCVSS 9,8İstismar yokEPSS %2chinamobile · intelligent home gateway firmware5 Eyl 2023
- CVE-2021-3929039İzleyin
Certain NetModule devices allow Limited Session Fixation via PHPSESSID.
KritikCVSS 9,8İstismar yokEPSS %2netmodule · netmodule router software23 Ağu 2021