CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2024-45368
HIGH
DirectLogic H2-DM1E < 2.8.0 - Session Fixation via Authentication Protocol Anomaly
CVSS 8.8
CVE-2024-42345
MEDIUM
SINEMA Remote Connect Server <V3.2 SP2 - Auth Bypass
CVSS 4.3
CVE-2024-7341
HIGH
Keycloak - Session Fixation via SAML Adapter
CVSS 7.1
CVE-2024-37829
HIGH
Outline <= 0.76.1 - Session Fixation via Crafted Magic Sign-In Link
CVSS 8.8
CVE-2024-38513
CRITICAL
Fiber < 2.52.5 - Session Fixation via User-Supplied Session ID
CVSS 10.0
CVE-2024-24552
HIGH
Bludit 3.14.0-3.14.9 - Session Fixation
CVSS 8.8
CVE-2024-25977
HIGH
HAWKI - Session Fixation via Login/Logout Functionality
CVSS 7.3
CVE-2024-23193
MEDIUM
OX App Suite < 8.22 - Unauthorized E-Mail Exposure via PDF Export Cache
CVSS 5.3
CVE-2024-2260
MEDIUM
zenml < 0.56.2 - Session Fixation via JWT Token Reuse
CVSS 4.2
CVE-2024-0157
MEDIUM
Dell Storage Resource Manager <4.9.0.0 - Privilege Escalation
CVSS 5.9
CVE-2024-30262
MEDIUM
Contao < 4.13.40 - Insufficient Session Expiration via Remember-Me Tokens
CVSS 5.9
CVE-2024-31221
MEDIUM
lizardbyte/sunshine 0.10.0-0.22.9 - Session Fixation via Device Unpairing Bypass
CVSS 5.9
CVE-2024-2639
MEDIUM
Bdtask Wholesale Inventory Management System <20240311 - Session Fi...
CVSS 4.3
CVE-2024-28197
HIGH
Zitadel < 2.44.3 - Session Hijacking via Subdomain Cookie Access
CVSS 7.5
CVE-2024-22250
HIGH
VMware Enhanced Authentication Plug-in - Session Hijack
CVSS 7.8
CVE-2024-22318
MEDIUM
IBM i Access Client Solutions <1.1.2-1.1.4, <1.1.4.3-1.1.9.4 - Info...
CVSS 5.1
CVE-2024-24823
MEDIUM
Graylog <5.1.11-5.2.4 - Privilege Escalation
CVSS 5.7
CVE-2024-23679
CRITICAL
Enonic XP < 7.7.4 - Unauthenticated Session Fixation
CVSS 9.8
CVE-2024-0351
LOW
SourceCodester Engineers Online Portal 1.0 - Info Disclosure
CVSS 3.1
CVE-2023-53776
HIGH
Screen SFT DAB 1.9.3 - Authentication Bypass via Session Fixation
CVSS 8.8
CVE-2023-53775
MEDIUM
Screen SFT DAB 1.9.3 - Unauthenticated Authentication Bypass via Session Fixation
CVSS 6.5
CVE-2023-53741
HIGH
Screen SFT DAB Series - Compact Radio DAB Transmitter 1.9.3 - Authentication Bypass via IP Session Reuse
CVSS 8.1
CVE-2023-52268
CRITICAL
FreeScout End-User Portal <1.0.65 - Auth Bypass
CVSS 9.1
CVE-2023-50176
HIGH
Fortinet FortiOS <7.4.3, <7.2.7, <7.0.13 - RCE
CVSS 7.5
CVE-2023-38018
MEDIUM
IBM Aspera Shares 1.10.0 PL2 - Privilege Escalation
CVSS 6.3
Details
Vulnerabilities
416