Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

570 CVEs tagged with CWE-61364 Critical, 179 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2026-15967

Published Jul 23, 2026

Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.3.

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-64829

Published Jul 22, 2026

Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obtained remember-me cookie to retain authenticated access by e…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5

CVE-2026-56583

Published Jul 21, 2026

HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session hijacking, and account misuse.

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9

CVE-2026-63753

Published Jul 20, 2026

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. Attackers can continue receiving real-time notifications unde…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-16206

Published Jul 19, 2026

A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators…

CVSS 5.3 · Medium
evidence mentions
7
Buzz score
27.3

CVE-2026-63089

Published Jul 16, 2026

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attacker…

CVSS 9.0 · Critical
evidence mentions
3
Buzz score
20.4

CVE-2026-63175

Published Jul 15, 2026

PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than instance-level variables. Consequently, multiple Capture obje…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-61452

Published Jul 15, 2026

The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued without a jti (JWT ID) claim…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-56400

Published Jul 15, 2026

open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated requests to the /api/v1/functi…

CVSS 9.0 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-48329

Published Jul 14, 2026

ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerabi…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-44383

Published Jul 10, 2026

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overw…

CVSS 8.7 · High
evidence mentions
3
Buzz score
28.9

CVE-2026-56665

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity management platform. From 3.0.0-rc.1 through 3.4.11 and from…

CVSS 4.2 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-56664

Published Jul 10, 2026

ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Provider validation in internal/idp/providers/jwt/session.go sk…

CVSS 4.2 · Medium
evidence mentions
5
Buzz score
22.9

CVE-2026-28564

Published Jul 10, 2026

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cached Credentials This issue aff…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0

CVE-2026-59219

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels,…

CVSS 7.1 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-54779

Published Jul 8, 2026

CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML token replay protection is inoperative because…

CVSS 5.9 · Medium
evidence mentions
6
Buzz score
24.5

CVE-2026-49229

Published Jul 7, 2026

Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks future OpenID login for that identity, while existing Actual…

CVSS 8.3 · High
evidence mentions
3
Buzz score
18.9

CVE-2026-42172

Published Jul 7, 2026

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Sanctum API tokens did not expire, allowing a leaked t…

CVSS 3.1 · Low
evidence mentions
4
Buzz score
21.1

CVE-2026-43918

Published Jul 6, 2026

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or marked inactive, existing aut…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-46455

Published Jul 6, 2026

Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAndVerifyAccessToken builds a Key…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-14725

Published Jul 5, 2026

A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality. Such manipulation leads to session…

CVSS 2.1 · Low
evidence mentions
6
Buzz score
31.0

CVE-2025-36359

Published Jun 30, 2026

IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the s…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2026-54479

Published Jun 25, 2026

The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementat…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2025-71335

Published Jun 25, 2026

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already h…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2026-9705

Published Jun 25, 2026

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to…

CVSS 6.5 · Medium
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort
Showing 1-25 of 570 CVEsPage 1 of 23