CWE-613 · 596 kayıt
Insufficient Session Expiration
Bu sınıftaki CVE’ler
597 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2014-2595Kavram kanıtı | Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authenticationbarracuda · web application firewall · CWE-613 | Kritik9,8 | — | %16,9 | 11 Şub 2020 |
41Planlayın | CVE-2020-27422Kavram kanıtı | In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the sanuko · time tracker · CWE-613 | Kritik9,8 | — | %7,9 | 16 Kas 2020 |
40Planlayın | CVE-2021-24019Kavram kanıtı | An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attackefortinet · forticlient endpoint management server · CWE-613 | Kritik9,8 | — | %3,9 | 6 Eki 2021 |
40Planlayın | CVE-2020-8234İstismar yok | A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be gui · edgemax firmware · CWE-613 | Kritik9,8 | — | %3,4 | 21 Ağu 2020 |
40Planlayın | CVE-2020-29667Kavram kanıtı | In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, calanatmservice · m3 atm monitoring system · CWE-613 | Kritik9,8 | — | %3,2 | 10 Ara 2020 |
40Planlayın | CVE-2016-6545İstismar yok | iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each requestieasytec · itrackeasy · CWE-613 | Kritik9,8 | — | %3,0 | 13 Tem 2018 |
40Planlayın | CVE-2021-3311İstismar yok | An issue was discovered in October through build 471.octobercms · october · CWE-613 | Kritik9,8 | — | %2,9 | 5 Şub 2021 |
40Planlayın | CVE-2018-21018İstismar yok | Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.joinmastodon · mastodon · CWE-613 | Kritik9,8 | — | %2,6 | 22 Eyl 2019 |
40Planlayın | CVE-2016-11014İstismar yok | NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.netgear · jnr1010 firmware · CWE-613 | Kritik9,8 | — | %2,5 | 16 Eki 2019 |
40Planlayın | CVE-2021-25981İstismar yok | Talkyard - Insufficient Session Expirationtalkyard · talkyard · CWE-613 | Kritik9,8 | — | %2,5 | 3 Oca 2022 |
40Planlayın | CVE-2020-35358İstismar yok | DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.domainmod · domainmod · CWE-613 | Kritik9,8 | — | %2,4 | 15 Mar 2021 |
40Planlayın | CVE-2019-8149İstismar yok | Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-613 | Kritik9,8 | — | %2,1 | 5 Kas 2019 |
40Planlayın | CVE-2020-27739İstismar yok | A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in ucitadel · webcit · CWE-613 | Kritik9,8 | — | %1,8 | 28 Eki 2020 |
39İzleyin | CVE-2021-25992İstismar yok | ifme - Insufficient Session Expirationif-me · ifme · CWE-613 | Kritik9,8 | — | %1,6 | 10 Şub 2022 |
39İzleyin | CVE-2020-27416İstismar yok | Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to cmahadiscom · mahavitaran · CWE-613 | Kritik9,8 | — | %1,6 | 8 Ara 2021 |
39İzleyin | CVE-2020-6649İstismar yok | An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexfortinet · fortiisolator · CWE-613 | Kritik9,8 | — | %1,5 | 8 Şub 2021 |
39İzleyin | CVE-2021-38823İstismar yok | The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.icehrm · icehrm · CWE-613 | Kritik9,8 | — | %1,5 | 4 Eki 2021 |
39İzleyin | CVE-2021-37333İstismar yok | Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.bookingcore · booking core · CWE-613 | Kritik9,8 | — | %1,5 | 4 Eki 2021 |
39İzleyin | CVE-2018-6634İstismar yok | A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain accessparsecgaming · parsec · CWE-613 | Kritik9,8 | — | %1,5 | 7 May 2019 |
39İzleyin | CVE-2016-5069İstismar yok | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.sierrawireless · aleos firmware · CWE-613 | Kritik9,8 | — | %1,4 | 9 Nis 2017 |
39İzleyin | CVE-2021-40849İstismar yok | In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited amahara · mahara · CWE-613 | Kritik9,8 | — | %1,4 | 3 Kas 2021 |
39İzleyin | CVE-2022-2713İstismar yok | Insufficient Session Expiration in cockpit-hq/cockpitagentejo · cockpit · CWE-613 | Kritik9,8 | — | %1,2 | 8 Ağu 2022 |
39İzleyin | CVE-2021-36330İstismar yok | Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.dell · emc streaming data platform · CWE-613 | Kritik9,8 | — | %1,2 | 30 Kas 2021 |
39İzleyin | CVE-2020-17474İstismar yok | A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary nezkteco · zkbiosecurity server · CWE-613 | Kritik9,8 | — | %1,2 | 14 Ağu 2020 |
39İzleyin | CVE-2015-5171İstismar yok | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Kritik9,8 | — | %1,2 | 24 Eki 2017 |
- CVE-2014-259544Planlayın
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a permanent authentication
KritikCVSS 9,8Kavram kanıtıEPSS %17barracuda · web application firewall11 Şub 2020
- CVE-2020-2742241Planlayın
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the s
KritikCVSS 9,8Kavram kanıtıEPSS %8anuko · time tracker16 Kas 2020
- CVE-2021-2401940Planlayın
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacke
KritikCVSS 9,8Kavram kanıtıEPSS %4fortinet · forticlient endpoint management server6 Eki 2021
- CVE-2020-823440Planlayın
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy web interface SIDSSL cookie for admin can be g
KritikCVSS 9,8İstismar yokEPSS %3ui · edgemax firmware21 Ağu 2020
- CVE-2020-2966740Planlayın
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, ca
KritikCVSS 9,8Kavram kanıtıEPSS %3lanatmservice · m3 atm monitoring system10 Ara 2020
- CVE-2016-654540Planlayın
iTrack Easy does not use session cookies to maintain sessions and POSTs the users password over HTTPS for each request
KritikCVSS 9,8İstismar yokEPSS %3ieasytec · itrackeasy13 Tem 2018
- CVE-2021-331140Planlayın
An issue was discovered in October through build 471.
KritikCVSS 9,8İstismar yokEPSS %3octobercms · october5 Şub 2021
- CVE-2018-2101840Planlayın
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
KritikCVSS 9,8İstismar yokEPSS %3joinmastodon · mastodon22 Eyl 2019
- CVE-2016-1101440Planlayın
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of the auth cookie is a special case.
KritikCVSS 9,8İstismar yokEPSS %3netgear · jnr1010 firmware16 Eki 2019
- CVE-2021-2598140Planlayın
Talkyard - Insufficient Session Expiration
KritikCVSS 9,8İstismar yokEPSS %2talkyard · talkyard3 Oca 2022
- CVE-2020-3535840Planlayın
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability.
KritikCVSS 9,8İstismar yokEPSS %2domainmod · domainmod15 Mar 2021
- CVE-2019-814940Planlayın
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
KritikCVSS 9,8İstismar yokEPSS %2magento · magento5 Kas 2019
- CVE-2020-2773940Planlayın
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated remote attackers to hijack recently logged-in u
KritikCVSS 9,8İstismar yokEPSS %2citadel · webcit28 Eki 2020
- CVE-2021-2599239İzleyin
ifme - Insufficient Session Expiration
KritikCVSS 9,8İstismar yokEPSS %2if-me · ifme10 Şub 2022
- CVE-2020-2741639İzleyin
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper OTP validation, allows remote attackers to c
KritikCVSS 9,8İstismar yokEPSS %2mahadiscom · mahavitaran8 Ara 2021
- CVE-2020-664939İzleyin
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unex
KritikCVSS 9,8İstismar yokEPSS %2fortinet · fortiisolator8 Şub 2021
- CVE-2021-3882339İzleyin
The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue.
KritikCVSS 9,8İstismar yokEPSS %2icehrm · icehrm4 Eki 2021
- CVE-2021-3733339İzleyin
Laravel Booking System Booking Core 2.0 is vulnerable to Session Management.
KritikCVSS 9,8İstismar yokEPSS %1bookingcore · booking core4 Eki 2021
- CVE-2018-663439İzleyin
A vulnerability in Parsec Windows 142-0 and Parsec 'Linux Ubuntu 16.04 LTS Desktop' Build 142-1 allows unauthorized users to maintain access
KritikCVSS 9,8İstismar yokEPSS %1parsecgaming · parsec7 May 2019
- CVE-2016-506939İzleyin
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.
KritikCVSS 9,8İstismar yokEPSS %1sierrawireless · aleos firmware9 Nis 2017
- CVE-2021-4084939İzleyin
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, the account associated with a web services token is vulnerable to being exploited a
KritikCVSS 9,8İstismar yokEPSS %1mahara · mahara3 Kas 2021
- CVE-2022-271339İzleyin
Insufficient Session Expiration in cockpit-hq/cockpit
KritikCVSS 9,8İstismar yokEPSS %1agentejo · cockpit8 Ağu 2022
- CVE-2021-3633039İzleyin
Dell EMC Streaming Data Platform versions before 1.3 contain an Insufficient Session Expiration Vulnerability.
KritikCVSS 9,8İstismar yokEPSS %1dell · emc streaming data platform30 Kas 2021
- CVE-2020-1747439İzleyin
A token-reuse vulnerability in ZKTeco FaceDepot 7B 1.0.213 and ZKBiosecurity Server 1.0.0_20190723 allows an attacker to create arbitrary ne
KritikCVSS 9,8İstismar yokEPSS %1zkteco · zkbiosecurity server14 Ağu 2020
- CVE-2015-517139İzleyin
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-release24 Eki 2017