Skip to main content

CWE archive

CWE-539 CVEs

Programmatic archive

7 CVEs tagged with CWE-5391 Critical, 2 High, 2 Medium, 2 Low, 0 Unrated.

CVE-2026-35192

Published May 5, 2026

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`…

CVSS 2.3 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-24318

Published Apr 14, 2026

Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse…

CVSS 4.2 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-52633

Published Feb 3, 2026

HCL AION is affected by a Permanent Cookie Containing Sensitive Session Information vulnerability. It is storing sensitive session data in persistent cookies may increase the risk…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-30861

Published May 2, 2023

Flask is a lightweight WSGI web application framework. When all of the following conditions are met, a response containing data intended for one client may be cached and subsequen…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27463

Published May 20, 2021

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attr…

CVSS 5.3 · Medium
Showing 1-7 of 7 CVEsPage 1 of 1