Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

569 CVEs tagged with CWE-61364 Critical, 178 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2021-25970

Published Oct 20, 2021

Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35214

Published Oct 12, 2021

The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user session upon password or email address change. When running multiple active sessions in se…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-25966

Published Oct 10, 2021

In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20473

Published Oct 7, 2021

IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41100

Published Oct 4, 2021

Wire-server is the backing server for the open source wire secure messaging application. In affected versions it is possible to trigger email address change of a user with only th…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38823

Published Oct 4, 2021

The IceHrm 30.0.0 OS website was found vulnerable to Session Management Issue. A signout from an admin account does not invalidate an admin session that is opened in a different b…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-37333

Published Oct 4, 2021

Laravel Booking System Booking Core 2.0 is vulnerable to Session Management. A password change at sandbox.bookingcore.org/user/profile/change-password does not invalidate a sessio…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-33982

Published Sep 8, 2021

An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other u…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29012

Published Sep 8, 2021

An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain information a…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37693

Published Aug 13, 2021

Discourse is an open-source platform for community discussion. In Discourse before versions 2.7.8 and 2.8.0.beta4, when adding additional email addresses to an existing account on…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-37156

Published Aug 5, 2021

Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-20378

Published Jul 7, 2021

IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-26037

Published Jul 7, 2021

An issue was discovered in Joomla! 2.5.0 through 3.9.27. CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-22221

Published Jun 8, 2021

An issue has been discovered in GitLab affecting all versions starting from 12.9.0 before 13.10.5, all versions starting from 13.11.0 before 13.11.5, all versions starting from 13…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-32923

Published Jun 3, 2021

HashiCorp Vault and Vault Enterprise allowed the renewal of nearly-expired token leases and dynamic secret leases (specifically, those within 1 second of their maximum TTL), which…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2020-10709

Published May 27, 2021

A security flaw was found in Ansible Tower when requesting an OAuth2 token with an OAuth2 application. Ansible Tower uses the token to provide authentication. This flaw allows an…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-22136

Published May 13, 2021

In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where the xpack.security.session.idleTimeout setting is not being respected. This was caus…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort
Showing 426-450 of 569 CVEsPage 18 of 23