Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

569 CVEs tagged with CWE-61364 Critical, 178 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2024-11668

Published Nov 26, 2024

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Long-lived connections could potentially…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-11208

Published Nov 14, 2024

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46892

Published Nov 12, 2024

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly invalidate sessions when the associated user is del…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-35473

Published Nov 10, 2024

An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker ca…

CVSS 9.1 · Critical

CVE-2024-52311

Published Nov 9, 2024

Authentication tokens issued via Cognito in data.all are not invalidated on log out, allowing for previously authenticated user to continue execution of authorized API Requests un…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48926

Published Oct 22, 2024

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions on the 13.x branch prior to 13.5.2, 10.x prior to 10.8.7,…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45462

Published Oct 16, 2024

The logout operation in the CloudStack web interface does not expire the user session completely which is valid until expiry by time or restart of the backend service. An attacker…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48827

Published Oct 11, 2024

An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-46040

Published Oct 7, 2024

IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration. The lack of validation of the authentication token at the IoT Haat during the Acc…

CVSS 6.5 · Medium

CVE-2024-23586

Published Sep 27, 2024

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthenticated attacker could obtain old session information.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-8888

Published Sep 18, 2024

An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1.0.4, could steal the tokens used on the web, since these have no expiration date t…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-38315

Published Sep 16, 2024

IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32006

Published Sep 10, 2024

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application does not expire the user session on reboot without logout.…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45187

Published Aug 23, 2024

Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-39809

Published Aug 14, 2024

The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-26288

Published Jul 30, 2024

IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system. IBM X-Force I…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29070

Published Jul 23, 2024

On versions before 2.1.4, session is not invalidated after logout. When the user logged in successfully, the Backend service returns "Authorization" as the front-end authenticatio…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort
Showing 226-250 of 569 CVEsPage 10 of 23