Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

569 CVEs tagged with CWE-61364 Critical, 178 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2021-31408

Published Apr 23, 2021

Authentication.logout() helper in com.vaadin:flow-client versions 5.0.0 prior to 6.0.0 (Vaadin 18), and 6.0.0 through 6.0.4 (Vaadin 19.0.0 through 19.0.3) uses incorrect HTTP meth…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3867

Published Mar 18, 2021

A vulnerability was found in the Quay web application. Sessions in the Quay web application never expire. An attacker, able to gain access to a session, could use it to control or…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-35358

Published Mar 15, 2021

DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On changing a password, both sessions using the changed password and old sessions in a…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2009-20001

Published Mar 7, 2021

An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still consi…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27351

Published Feb 19, 2021

The Terminate Session feature in the Telegram application through 7.2.1 for Android, and through 2.4.7 for Windows and UNIX, fails to invalidate a recently active session.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21032

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation of this issue could lead t…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-21031

Published Feb 11, 2021

Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not adequately invalidate user sessions. Successful exploitation could lead to unauthorized…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26921

Published Feb 9, 2021

In util/session/sessionmanager.go in Argo CD before 1.8.4, tokens continue to work even when the user account is disabled.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-6649

Published Feb 8, 2021

An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired admin user session IDs to gain ad…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2021-3311

Published Feb 5, 2021

An issue was discovered in October through build 471. It reactivates an old session ID (which had been invalid after a logout) once a new login occurs. NOTE: this violates the int…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-14247

Published Feb 4, 2021

HCL OneTest Performance V9.5, V10.0, V10.1 contains an inadequate session timeout, which could allow an attacker time to guess and use a valid session ID.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3183

Published Jan 19, 2021

Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15220

Published Jan 13, 2021

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, two cookies are created for the same session, which leads to a possibility to stea…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-15218

Published Jan 13, 2021

Combodo iTop is a web based IT Service Management tool. In iTop before versions 2.7.2 and 3.0.0, admin pages are cached, so that their content is visible after deconnection by usi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-20007

Published Jan 1, 2021

The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-29667

Published Dec 10, 2020

In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cookie value, such as PHPSESSID=LANIT-IMANAGER, can achieve control over the system becau…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-4696

Published Nov 30, 2020

IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could allow an authenticated user to obtain sensitive information from the previous session…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-13353

Published Nov 17, 2020

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

CVSS 2.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-27422

Published Nov 16, 2020

In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire once used, allowing an attacker to use the same link to takeover the account.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-23140

Published Nov 9, 2020

Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or dev…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-15950

Published Nov 5, 2020

Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-25374

Published Oct 28, 2020

CyberArk Privileged Session Manager (PSM) 10.9.0.15 allows attackers to discover internal pathnames by reading an error popup message after two hours of idle time.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort
Showing 451-475 of 569 CVEsPage 19 of 23