Skip to main content

CWE archive

CWE-384 CVEs

Programmatic archive

416 CVEs tagged with CWE-38473 Critical, 151 High, 164 Medium, 27 Low, 1 Unrated.

CVE-2026-16496

Published Jul 28, 2026

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow a user who obtains another use…

CVSS 8.9 · High
evidence mentions
1
Buzz score
11.9

CVE-2021-32088

Published Jul 27, 2026

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize a brute-force attack. This pro…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
16.0

CVE-2026-16089

Published Jul 17, 2026

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not properly bound to the client that…

CVSS 5.4 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-59883

Published Jul 8, 2026

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, be…

CVSS 4.7 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-14609

Published Jul 3, 2026

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results…

CVSS 2.9 · Low
evidence mentions
5
Buzz score
27.9

CVE-2026-13707

Published Jul 1, 2026

Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/Backend/MWOAuthServer.Php. This issue affects OAuth: fro…

CVSS 0.0 · Unrated
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-56224

Published Jun 30, 2026

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users without confirmation. Attackers ca…

CVSS 5.1 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-35095

Published Jun 30, 2026

KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid name is set, its value remains unchanged after successful…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-40082

Published Jun 25, 2026

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regenerate_id() after login, leading to Session Fixation. sessio…

CVSS 5.4 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-56425

Published Jun 22, 2026

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers to bypass important sec…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-12581

Published Jun 22, 2026

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's pri…

CVSS 7.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-53900

Published Jun 16, 2026

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument, allowing a malicious site to inject arbitrary cookies int…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2009-10007

Published Jun 9, 2026

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the…

CVSS 9.1 · Critical
evidence mentions
5
Buzz score
29.4

CVE-2026-41839

Published Jun 9, 2026

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID fo…

CVSS 4.2 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-11335

Published Jun 5, 2026

A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
26.0

CVE-2025-67446

Published Jun 4, 2026

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-33384

Published May 29, 2026

QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker t…

CVSS 4.8 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2026-48545

Published May 27, 2026

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTT…

CVSS 7.6 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-43827

Published May 25, 2026

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgr…

CVSS 5.9 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-45773

Published May 15, 2026

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF…

CVSS 5.1 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30808

Published May 12, 2026

Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800

CVSS 7.6 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-65415

Published May 11, 2026

docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.

CVSS 5.4 · Medium

CVE-2026-40010

Published May 6, 2026

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket. This issue affects Ap…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-46605

Published Apr 17, 2026

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged att…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 416 CVEsPage 1 of 17