Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

569 CVEs tagged with CWE-61364 Critical, 178 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2025-50484

Published Jul 28, 2025

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to execute a session hijacking attack.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-50491

Published Jul 28, 2025

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v1 allows attackers to execute a session hijacking attack.

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31952

Published Jul 24, 2025

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized acce…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53826

Published Jul 15, 2025

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename, and edit files. In version 2.39.0, File Browser…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53642

Published Jul 11, 2025

haxcms-nodejs and haxcms-php are backends for HAXcms. The logout function within the application does not terminate a user's session or clear their cookies. Additionally, the appl…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-4407

Published Jun 30, 2025

Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

CVSS 6.8 · Medium

CVE-2025-49152

Published Jun 25, 2025

The affected products contain JSON Web Tokens (JWT) that do not expire, which could allow an attacker to gain access to the system.

CVSS 8.7 · High

CVE-2025-4754

Published Jun 17, 2025

Insufficient Session Expiration vulnerability in ash-project ash_authentication_phoenix allows Session Hijacking. This vulnerability is associated with program files lib/ash_authe…

CVSS 2.3 · Low

CVE-2024-50562

Published Jun 10, 2025

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-33005

Published Jun 1, 2025

IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48929

Published May 28, 2025

The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token with a short expiration time) that can be reused at a later…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48061

Published May 22, 2025

wire-webapp is the web application for the open-source messaging service Wire. A change caused a regression resulting in sessions not being properly invalidated. A user that logge…

CVSS 5.6 · Medium

CVE-2025-0138

Published May 14, 2025

Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not expire when users are deleted, which makes Prisma Cloud Compute Edition susceptible to…

CVSS 2.0 · Low
evidence mentions
1
Buzz score
11.9

CVE-2025-40566

Published May 13, 2025

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1). Affected products do not correctly…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46741

Published May 12, 2025

A suspended or recently logged-out user could continue to interact with Blueframe until the time-out period occurred.

CVSS 5.7 · Medium

CVE-2025-4528

Published May 11, 2025

A weakness has been identified in Dígitro NGC Explorer up to 3.44.15/3.48.21. This affects an unknown function. Executing a manipulation can lead to session expiration. The attack…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-46336

Published May 8, 2025

Rack::Session is a session management implementation for Rack. In versions starting from 2.0.0 to before 2.1.1, when using the Rack::Session::Pool middleware, and provided the att…

CVSS 4.2 · Medium

CVE-2025-32441

Published May 7, 2025

Rack is a modular Ruby web server interface. Prior to version 2.2.14, when using the `Rack::Session::Pool` middleware, simultaneous rack requests can restore a deleted rack sessio…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46815

Published May 6, 2025

The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API. This API enables the use of IdPs for authentication, know…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46344

Published Apr 29, 2025

The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. Versions starting from 4.0.1 and prior to 4.5.1, do not invoke `.setExpirationTime…

CVSS 4.9 · Medium

CVE-2025-2185

Published Apr 25, 2025

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient session expiration vulnerability, which could permit an atta…

CVSS 8.5 · High
Showing 176-200 of 569 CVEsPage 8 of 23