İçeriğe atla
Noroxi

CWE-488 · 37 kayıt

Exposure of Data Element to Wrong Session

Bu sınıftaki CVE’ler

37 kayıt

  • CVE-2024-38367
    41Planlayın

    CoacoaPods trunk sessions verification step could be manipulated for owner session hijacking

    KritikCVSS 9,6İstismar yokEPSS %11

    cocoapods · trunk.cocoapods.org1 Tem 2024

  • CVE-2026-16326
    40Planlayın

    consul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    KritikCVSS 10,0İstismar yokEPSS %1

    hashicorp · tooling29 Tem 2026

  • CVE-2026-16498
    40Planlayın

    terraform-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless mode

    KritikCVSS 10,0İstismar yokEPSS %0

    hashicorp · tooling28 Tem 2026

  • CVE-2026-19931
    39İzleyin

    Negotiate ambient user conn reuse

    KritikCVSS 9,8İstismar yokEPSS %1

    haxx · curl6 Eyl 2026

  • CVE-2024-27455
    36İzleyin

    In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts

    KritikCVSS 9,1İstismar yokEPSS %1

    26 Şub 2024

  • CVE-2025-47928
    36İzleyin

    Spotipy repo vulnerable to secrets exfiltration via `pull_request_target`

    KritikCVSS 9,1Kavram kanıtıEPSS %1

    spotipy-dev · spotipy15 May 2025

  • CVE-2026-86492
    34İzleyin

    In JetBrains YouTrack before 2026.2.18634 a shared token cache allowed cross-tenant theft of GitHub App installation tokens

    YüksekCVSS 8,5İstismar yokEPSS %1

    jetbrains · youtrack7 Eyl 2026

  • CVE-2025-1247
    33İzleyin

    Io.quarkus:quarkus-rest: quarkus rest endpoint request parameter leakage due to shared instance

    YüksekCVSS 8,3İstismar yokEPSS %1

    red hat · red hat build of apache camel 4.8 for quarkus 3.1513 Şub 2025

  • CVE-2024-27935
    33İzleyin

    Deno's Node.js Compatibility Runtime has Cross-Session Data Contamination

    YüksekCVSS 8,3İstismar yokEPSS %1

    deno · deno20 Mar 2024

  • TYPO3 Security Misconfiguration in Frontend Session Handling

    YüksekCVSS 8,2İstismar yok

    Packagist · typo3/cms-core30 May 2024

  • CVE-2024-6162
    31İzleyin

    Undertow: url-encoded request path information can be broken on ajp-listener

    YüksekCVSS 7,5İstismar yokEPSS %2

    red hat · eap 8.0.120 Haz 2024

  • CVE-2022-40210
    31İzleyin

    Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enab

    YüksekCVSS 7,8İstismar yokEPSS %0

    intel · data center manager10 May 2023

  • CVE-2026-80231
    30İzleyin

    native CA store conn reuse

    YüksekCVSS 7,5İstismar yokEPSS %1

    haxx · curl6 Eyl 2026

  • CVE-2026-5773
    30İzleyin

    wrong reuse of SMB connection

    YüksekCVSS 7,5İstismar yokEPSS %1

    haxx · curl13 May 2026

  • CVE-2024-5148
    30İzleyin

    Gnome-remote-desktop: inadequate validation of session agents using d-bus methods may expose rdp tls certificate

    YüksekCVSS 7,5İstismar yokEPSS %1

    red hat · red hat enterprise linux 102 Eyl 2024

  • CVE-2023-6519
    30İzleyin

    Seeing admin password hash value in Mia Technology's Mia-Med

    YüksekCVSS 7,5İstismar yokEPSS %1

    miateknoloji · mia-med8 Şub 2024

  • CVE-2023-1907
    30İzleyin

    Pgadmin: users authenticated simultaneously via ldap may be attached to the wrong session

    YüksekCVSS 7,5İstismar yokEPSS %0

    pgadmin · pgadmin9 Oca 2025

  • CVE-2025-30073
    30İzleyin

    An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0.

    YüksekCVSS 7,5İstismar yokEPSS %0

    26 Mar 2025

  • CVE-2024-41977
    29İzleyin

    A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM

    YüksekCVSS 7,3İstismar yokEPSS %0

    siemens · ruggedcom rm1224 lte\(4g\) eu firmware13 Ağu 2024

  • CVE-2026-88017
    29İzleyin

    rclone: FTP cross-session auth-proxy backend confusion

    YüksekCVSS 7,3İstismar yokEPSS %0

    rclone · rclone10 Eyl 2026

  • CVE-2026-18489
    29İzleyin

    IBM ContextForge Translate is affected by cross-client credential context confusion

    YüksekCVSS 7,4İstismar yokEPSS %0

    ibm · contextforge4 Eyl 2026

  • CVE-2026-23919
    28İzleyin

    Insufficient isolation of JavaScript (Duktape) execution context on Zabbix Server

    YüksekCVSS 7,1İstismar yokEPSS %0

    zabbix · zabbix24 Mar 2026

  • CVE-2026-8458
    26İzleyin

    wrong reuse for different services

    OrtaCVSS 6,5İstismar yokEPSS %0

    haxx · curl3 Tem 2026

  • CVE-2026-23646
    26İzleyin

    OpenProject users can delete other user's session, causing them to be logged out

    OrtaCVSS 6,5İstismar yokEPSS %0

    openproject · openproject19 Oca 2026

  • CVE-2026-84685
    26İzleyin

    Improper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential Management

    OrtaCVSS 6,5İstismar yokEPSS %0

    auth0 · react-native-auth08 Eyl 2026

Tüm zafiyet sınıfları