CWE-488 · 37 kayıt
Exposure of Data Element to Wrong Session
Bu sınıftaki CVE’ler
37 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2024-38367İstismar yok | CoacoaPods trunk sessions verification step could be manipulated for owner session hijackingcocoapods · trunk.cocoapods.org · CWE-488 | Kritik9,6 | — | %11,1 | 1 Tem 2024 |
40Planlayın | CVE-2026-16326İstismar yok | consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modehashicorp · tooling · CWE-488 | Kritik10,0 | — | %0,5 | 29 Tem 2026 |
40Planlayın | CVE-2026-16498İstismar yok | terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modehashicorp · tooling · CWE-488 | Kritik10,0 | — | %0,5 | 28 Tem 2026 |
39İzleyin | CVE-2026-19931İstismar yok | Negotiate ambient user conn reusehaxx · curl · CWE-488 | Kritik9,8 | — | %0,7 | 6 Eyl 2026 |
36İzleyin | CVE-2024-27455İstismar yok | In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attemptsCWE-488 | Kritik9,1 | — | %0,6 | 26 Şub 2024 |
36İzleyin | CVE-2025-47928Kavram kanıtı | Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`spotipy-dev · spotipy · CWE-488 | Kritik9,1 | — | %0,6 | 15 May 2025 |
34İzleyin | CVE-2026-86492İstismar yok | In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokensjetbrains · youtrack · CWE-488 | Yüksek8,5 | — | %0,9 | 7 Eyl 2026 |
33İzleyin | CVE-2025-1247İstismar yok | Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instancered hat · red hat build of apache camel 4.8 for quarkus 3.15 · CWE-488 | Yüksek8,3 | — | %0,8 | 13 Şub 2025 |
33İzleyin | CVE-2024-27935İstismar yok | Deno's Node.js Compatibility Runtime has Cross-Session Data Contaminationdeno · deno · CWE-488 | Yüksek8,3 | — | %0,7 | 20 Mar 2024 |
32İzleyin | GHSA-82vp-jr39-4j2jİstismar yok | TYPO3 Security Misconfiguration in Frontend Session HandlingPackagist · typo3/cms-core · CWE-488 | Yüksek8,2 | — | — | 30 May 2024 |
31İzleyin | CVE-2024-6162İstismar yok | Undertow: url-encoded request path information can be broken on ajp-listenerred hat · eap 8.0.1 · CWE-488 | Yüksek7,5 | — | %1,7 | 20 Haz 2024 |
31İzleyin | CVE-2022-40210İstismar yok | Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enabintel · data center manager · CWE-488 | Yüksek7,8 | — | %0,2 | 10 May 2023 |
30İzleyin | CVE-2026-80231İstismar yok | native CA store conn reusehaxx · curl · CWE-488 | Yüksek7,5 | — | %0,9 | 6 Eyl 2026 |
30İzleyin | CVE-2026-5773İstismar yok | wrong reuse of SMB connectionhaxx · curl · CWE-488 | Yüksek7,5 | — | %0,7 | 13 May 2026 |
30İzleyin | CVE-2024-5148İstismar yok | Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificatered hat · red hat enterprise linux 10 · CWE-488 | Yüksek7,5 | — | %0,6 | 2 Eyl 2024 |
30İzleyin | CVE-2023-6519İstismar yok | Seeing admin password hash value in Mia Technology's Mia-Medmiateknoloji · mia-med · CWE-488 | Yüksek7,5 | — | %0,5 | 8 Şub 2024 |
30İzleyin | CVE-2023-1907İstismar yok | Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong sessionpgadmin · pgadmin · CWE-488 | Yüksek7,5 | — | %0,4 | 9 Oca 2025 |
30İzleyin | CVE-2025-30073İstismar yok | An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.CWE-488 | Yüksek7,5 | — | %0,4 | 26 Mar 2025 |
29İzleyin | CVE-2024-41977İstismar yok | A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM siemens · ruggedcom rm1224 lte\(4g\) eu firmware · CWE-488 | Yüksek7,3 | — | %0,4 | 13 Ağu 2024 |
29İzleyin | CVE-2026-88017İstismar yok | rclone: FTP cross-session auth-proxy backend confusionrclone · rclone · CWE-488 | Yüksek7,3 | — | %0,4 | 10 Eyl 2026 |
29İzleyin | CVE-2026-18489İstismar yok | IBM ContextForge Translate is affected by cross-client credential context confusionibm · contextforge · CWE-488 | Yüksek7,4 | — | %0,3 | 4 Eyl 2026 |
28İzleyin | CVE-2026-23919İstismar yok | Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Serverzabbix · zabbix · CWE-488 | Yüksek7,1 | — | %0,2 | 24 Mar 2026 |
26İzleyin | CVE-2026-8458İstismar yok | wrong reuse for different serviceshaxx · curl · CWE-488 | Orta6,5 | — | %0,4 | 3 Tem 2026 |
26İzleyin | CVE-2026-23646İstismar yok | OpenProject users can delete other user's session, causing them to be logged outopenproject · openproject · CWE-488 | Orta6,5 | — | %0,4 | 19 Oca 2026 |
26İzleyin | CVE-2026-84685İstismar yok | Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Managementauth0 · react-native-auth0 · CWE-488 | Orta6,5 | — | %0,3 | 8 Eyl 2026 |
- CVE-2024-3836741Planlayın
CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking
KritikCVSS 9,6İstismar yokEPSS %11cocoapods · trunk.cocoapods.org1 Tem 2024
- CVE-2026-1632640Planlayın
consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
KritikCVSS 10,0İstismar yokEPSS %1hashicorp · tooling29 Tem 2026
- CVE-2026-1649840Planlayın
terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode
KritikCVSS 10,0İstismar yokEPSS %0hashicorp · tooling28 Tem 2026
- CVE-2026-1993139İzleyin
Negotiate ambient user conn reuse
KritikCVSS 9,8İstismar yokEPSS %1haxx · curl6 Eyl 2026
- CVE-2024-2745536İzleyin
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts
KritikCVSS 9,1İstismar yokEPSS %126 Şub 2024
- CVE-2025-4792836İzleyin
Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`
KritikCVSS 9,1Kavram kanıtıEPSS %1spotipy-dev · spotipy15 May 2025
- CVE-2026-8649234İzleyin
In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens
YüksekCVSS 8,5İstismar yokEPSS %1jetbrains · youtrack7 Eyl 2026
- CVE-2025-124733İzleyin
Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance
YüksekCVSS 8,3İstismar yokEPSS %1red hat · red hat build of apache camel 4.8 for quarkus 3.1513 Şub 2025
- CVE-2024-2793533İzleyin
Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination
YüksekCVSS 8,3İstismar yokEPSS %1deno · deno20 Mar 2024
- GHSA-82vp-jr39-4j2j32İzleyin
TYPO3 Security Misconfiguration in Frontend Session Handling
YüksekCVSS 8,2İstismar yokPackagist · typo3/cms-core30 May 2024
- CVE-2024-616231İzleyin
Undertow: url-encoded request path information can be broken on ajp-listener
YüksekCVSS 7,5İstismar yokEPSS %2red hat · eap 8.0.120 Haz 2024
- CVE-2022-4021031İzleyin
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enab
YüksekCVSS 7,8İstismar yokEPSS %0intel · data center manager10 May 2023
- CVE-2026-8023130İzleyin
native CA store conn reuse
YüksekCVSS 7,5İstismar yokEPSS %1haxx · curl6 Eyl 2026
- CVE-2026-577330İzleyin
wrong reuse of SMB connection
YüksekCVSS 7,5İstismar yokEPSS %1haxx · curl13 May 2026
- CVE-2024-514830İzleyin
Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate
YüksekCVSS 7,5İstismar yokEPSS %1red hat · red hat enterprise linux 102 Eyl 2024
- CVE-2023-651930İzleyin
Seeing admin password hash value in Mia Technology's Mia-Med
YüksekCVSS 7,5İstismar yokEPSS %1miateknoloji · mia-med8 Şub 2024
- CVE-2023-190730İzleyin
Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session
YüksekCVSS 7,5İstismar yokEPSS %0pgadmin · pgadmin9 Oca 2025
- CVE-2025-3007330İzleyin
An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.
YüksekCVSS 7,5İstismar yokEPSS %026 Mar 2025
- CVE-2024-4197729İzleyin
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM
YüksekCVSS 7,3İstismar yokEPSS %0siemens · ruggedcom rm1224 lte\(4g\) eu firmware13 Ağu 2024
- CVE-2026-8801729İzleyin
rclone: FTP cross-session auth-proxy backend confusion
YüksekCVSS 7,3İstismar yokEPSS %0rclone · rclone10 Eyl 2026
- CVE-2026-1848929İzleyin
IBM ContextForge Translate is affected by cross-client credential context confusion
YüksekCVSS 7,4İstismar yokEPSS %0ibm · contextforge4 Eyl 2026
- CVE-2026-2391928İzleyin
Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server
YüksekCVSS 7,1İstismar yokEPSS %0zabbix · zabbix24 Mar 2026
- CVE-2026-845826İzleyin
wrong reuse for different services
OrtaCVSS 6,5İstismar yokEPSS %0haxx · curl3 Tem 2026
- CVE-2026-2364626İzleyin
OpenProject users can delete other user's session, causing them to be logged out
OrtaCVSS 6,5İstismar yokEPSS %0openproject · openproject19 Oca 2026
- CVE-2026-8468526İzleyin
Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management
OrtaCVSS 6,5İstismar yokEPSS %0auth0 · react-native-auth08 Eyl 2026