Skip to main content

CWE archive

CWE-613 CVEs

Programmatic archive

570 CVEs tagged with CWE-61364 Critical, 179 High, 265 Medium, 62 Low, 0 Unrated.

CVE-2023-49091

Published Nov 29, 2023

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. Cosmos-server is vulnerable due to to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47628

Published Nov 14, 2023

DataHub is an open-source metadata platform. DataHub Frontend's sessions are configured using Play Framework's default settings for stateless session which do not set an expiratio…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-39695

Published Oct 31, 2023

Insufficient session expiration in Elenos ETG150 FM Transmitter v3.12 allows attackers to arbitrarily change transmitter configuration and data after logging out.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-5865

Published Oct 31, 2023

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-5838

Published Oct 29, 2023

Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-46158

Published Oct 25, 2023

IBM WebSphere Application Server Liberty 23.0.0.9 through 23.0.0.10 could provide weaker than expected security due to improper resource expiration handling. IBM X-Force ID: 268…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37504

Published Oct 19, 2023

HCL Compass is vulnerable to failure to invalidate sessions. The application does not invalidate authenticated sessions when the log out functionality is called.  If the session i…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-45659

Published Oct 17, 2023

Engelsystem is a shift planning system for chaos events. If a users' password is compromised and an attacker gained access to a users' account, i.e., logged in and obtained a ses…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-33303

Published Oct 13, 2023

A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api request

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-3916

Published Sep 20, 2023

A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root ses…

CVSS 6.8 · Medium

CVE-2023-40732

Published Sep 12, 2023

A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application does not invalidate the session token on logout. T…

CVSS 3.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-41041

Published Aug 30, 2023

Graylog is a free and open log management platform. In a multi-node Graylog cluster, after a user has explicitly logged out, a user session may still be used for API requests unti…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-40178

Published Aug 23, 2023

Node-SAML is a SAML library not dependent on any frameworks that runs in Node. The lack of checking of current timestamp allows a LogoutRequest XML to be reused multiple times eve…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40025

Published Aug 23, 2023

Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. All versions of Argo CD starting from version 2.6.0 have a bug where open web terminal sessions do not ex…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40174

Published Aug 18, 2023

Social media skeleton is an uncompleted/framework social media project implemented using a php, css ,javascript and html. Insufficient session expiration is a web application secu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37570

Published Aug 8, 2023

This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing the stolen cookie, a remote attacker could gain unauthorized…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2023-4190

Published Aug 6, 2023

Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-4126

Published Aug 3, 2023

Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-38489

Published Jul 27, 2023

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 affects all Kirby sites with user accounts (unless Kirby's…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37919

Published Jul 25, 2023

Cal.com is open-source scheduling software. A vulnerability allows active sessions associated with an account to remain active even after enabling 2FA. When activating 2FA on a Ca…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 301-325 of 570 CVEsPage 13 of 23