CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2026-33492
HIGH
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
CVSS 7.3
CVE-2026-30224
MEDIUM
olivetin < 3000.11.1 - Session Fixation via Incomplete Logout
CVSS 5.4
CVE-2026-24352
CRITICAL
PluXml CMS 5.8.21/5.9.0-rc7 - Session Fixation
CVSS 9.8
CVE-2026-24894
HIGH
FrankenPHP <1.11.2 - Info Disclosure
CVSS 7.5
CVE-2026-2177
HIGH
SourceCodester Prison Management System 1.0 - Session Fixation
CVSS 7.3
CVE-2026-23796
CRITICAL
Quick.Cart <6.7 - Session Hijacking
CVSS 9.8
CVE-2026-23624
MEDIUM
GLPI <10.0.23-11.0.5 - Info Disclosure
CVSS 4.3
CVE-2026-22082
HIGH
Tenda Wireless Router - Auth Bypass
CVE-2025-67446
CRITICAL
Neterbit NW-431F Router <= 20241014-IR03 - Unauthenticated Authentication Bypass via Weak Cookie Value
CVSS 9.8
CVE-2025-65415
MEDIUM
docuFORM Managed Print Service Client 11.11c - Session Fixation
CVSS 5.4
CVE-2025-46605
MEDIUM
Dell PowerProtect Data Domain 8.4-8.5 - Session Fixation
CVSS 6.2
CVE-2025-55266
MEDIUM
HCL Aftermarket DPC is affected by Session Fixation
CVSS 5.9
CVE-2025-70973
MEDIUM
ScadaBR 1.12.4 - Session Fixation via JSESSIONID Cookie
CVSS 4.8
CVE-2025-71057
HIGH
D-Link DSL-124 ME_1.00 - Session Hijacking
CVSS 8.2
CVE-2025-7014
MEDIUM
QR Menu Pro Smart Menu Systems Menu Panel <29012026 - Session Fixation
CVSS 5.7
CVE-2025-7015
MEDIUM
QR Menu <s1.05.12 - Session Fixation
CVSS 5.7
CVE-2025-69602
CRITICAL
AltumCode 66biolinks v62.0.0 - Session Fixation
CVSS 9.1
CVE-2025-68139
MEDIUM
EVerest <2025.12.1 - Info Disclosure
CVSS 4.3
CVE-2025-36115
MEDIUM
IBM Sterling Connect:Express Adapter - Privilege Escalation
CVSS 6.3
CVE-2025-43516
LOW
macOS <26.2-15.7.3-14.8.3 - Info Disclosure
CVSS 3.3
CVE-2025-63529
MEDIUM
Blood Bank Management System 1.0 - Session Fixation
CVSS 6.1
CVE-2025-65681
LOW
Overhang.IO <20.0.2 - Info Disclosure
CVSS 3.3
CVE-2025-56400
HIGH
Tuya Smart and Smartlife - Cross-Site Request Forgery in OAuth Account Linking Flow
CVSS 8.8
CVE-2025-63224
CRITICAL
Itel DAB Encoder <25aec8d - Auth Bypass
CVSS 10.0
CVE-2025-63216
CRITICAL
Itel DAB Gateway Firmware - Authentication Bypass via JWT Token Reuse
CVSS 10.0
Details
Vulnerabilities
416