CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2018-18925
CRITICAL
Gogs < 0.11.66 - Remote Code Execution via Session File Forgery
CVSS 9.8
CVE-2018-13282
MEDIUM
Synology Photo Station <6.8.7-3481 - Info Disclosure
CVSS 5.6
CVE-2018-16463
LOW
Nextcloud Server <14.0.0-12.0.8 - Info Disclosure
CVSS 3.1
CVE-2018-18380
MEDIUM
BigTree CMS < 4.2.24 - Session Fixation via admin.php
CVSS 5.4
CVE-2018-17902
MEDIUM
Yokogawa STARDOM Controllers FCJ FCN-100 FCN-RTU FCN-500 < R4.10 - Denial of Service via Session Management
CVSS 5.3
CVE-2018-9082
HIGH
Iomega LenovoEMC NAS <4.1.402.34662 - Privilege Escalation
CVSS 8.8
CVE-2018-8852
HIGH
Philips e-Alert Unit <R2.1 - Info Disclosure
CVSS 8.8
CVE-2018-1127
MEDIUM
Red Hat Gluster Storage <3.4.0 - Info Disclosure
CVSS 4.2
CVE-2018-5385
HIGH
Navarino Infinity - Session Fixation
CVSS 8.8
CVE-2018-14387
HIGH
WonderCMS < 2.5.2 - Session Fixation
CVSS 8.8
CVE-2018-1492
MEDIUM
IBM Jazz Foundation - Privilege Escalation
CVSS 4.3
CVE-2018-1000602
MEDIUM
Jenkins SAML Plugin <1.0.6 - Privilege Escalation
CVSS 5.9
CVE-2018-1000519
MEDIUM
aio-libs aiohttp-session - Session Fixation
CVSS 6.5
CVE-2018-12538
HIGH
Eclipse Jetty <9.4.8 - Privilege Escalation
CVSS 8.8
CVE-2018-0359
MEDIUM
Cisco Meeting Server - Session Fixation
CVSS 5.5
CVE-2018-9026
HIGH
CA Privileged Access Manager 2.x - Session Fixation
CVSS 7.5
CVE-2018-12071
CRITICAL
CodeIgniter <3.1.9 - Info Disclosure
CVSS 9.8
CVE-2018-11385
HIGH
Symfony Security 2.7.0-2.7.47 - Session Fixation via Guard Login Feature
CVSS 8.1
CVE-2018-11714
CRITICAL
TP-Link TL-WR840N/TL-WR841N <5 - Info Disclosure
CVSS 9.8
CVE-2018-11571
HIGH
ClipperCMS 1.3.3 - Session Fixation
CVSS 8.8
CVE-2018-11567
LOW
Amazon Echo <2018-04-27 - Info Disclosure
CVSS 3.3
CVE-2018-1375
MEDIUM
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 - Session ...
CVSS 5.9
CVE-2018-11475
HIGH
Monstra CMS 3.0.4 - Info Disclosure
CVSS 8.0
CVE-2018-11474
HIGH
Monstra CMS 3.0.4 - Info Disclosure
CVSS 8.0
CVE-2018-1148
MEDIUM
Nessus <7.1.0 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities
416