Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

569 CVEs tagged with CWE-61364 Critical, 178 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2021-47663

Published Apr 24, 2025

Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access.

CVSS 8.1 · High

CVE-2025-42602

Published Apr 23, 2025

This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh tokens in certain API endpoints of authentication process. A remote attacker could e…

CVSS 8.2 · High

CVE-2025-28059

Published Apr 18, 2025

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale toke…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24859

Published Apr 14, 2025

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not properly invalidated after password changes. When a user's passw…

CVSS 2.1 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-30516

Published Apr 14, 2025

Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices…

CVSS 2.0 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-1968

Published Apr 9, 2025

Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay…

CVSS 7.7 · High

CVE-2025-28132

Published Apr 1, 2025

A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse session tokens even after a user logs out, leading to unauthorized access and account t…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2596

Published Mar 26, 2025

Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-57056

Published Feb 18, 2025

Incorrect cookie session handling in WombatDialer before 25.02 results in the full session identity being written to system logs and could be used by a malicious attacker to imper…

CVSS 5.4 · Medium

CVE-2025-1198

Published Feb 13, 2025

An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2 meant that long-lived connections in ActionCa…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24973

Published Feb 11, 2025

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process,…

CVSS 9.3 · Critical

CVE-2025-24896

Published Feb 11, 2025

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-alpha.0, a login token named `token` is stored in a cookie f…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45386

Published Feb 11, 2025

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1…

CVSS 8.7 · High

CVE-2024-13280

Published Jan 9, 2025

Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Persistent Login: from 0.0.0 before 1.8.0, from 2.0.* before 2…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45033

Published Jan 8, 2025

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Provider: before 1.5.2. When user password has been changed w…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11627

Published Jan 7, 2025

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Sitefinity: from 4.0 through 14.4.8142, from 15.0.8200 through…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22386

Published Jan 4, 2025

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of activ…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56413

Published Jan 2, 2025

Missing session invalidation after user deletion. The following products are affected: Acronis Cyber Protect 16 (Windows) before build 39169.

CVSS 6.1 · Medium

CVE-2024-56351

Published Dec 20, 2024

In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-55603

Published Dec 19, 2024

Kanboard is project management software that focuses on the Kanban methodology. In affected versions sessions are still usable even though their lifetime has exceeded. Kanboard im…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12667

Published Dec 16, 2024

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unknown functionality of the file /invoices/view. The manipulat…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 569 CVEsPage 9 of 23