CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
404 vulnerabilities with CWE-384
CVE-2023-46733
MEDIUM
Symfony <5.4.31 & <6.3.8 - Info Disclosure
CVSS 6.5
CVE-2023-5309
MEDIUM
Puppet Enterprise <2021.7.6,2023.5 - Privilege Escalation
CVSS 6.8
CVE-2023-0897
HIGH
Sielco PolyEco1000 - Info Disclosure
CVSS 8.8
CVE-2023-45687
HIGH
South River Technologies - Privilege Escalation
CVSS 8.8
CVE-2023-44400
MEDIUM
Uptime Kuma <1.23.3 - Privilege Escalation
CVSS 6.7
CVE-2023-42322
CRITICAL
icmsdev iCMS 7.0.16 - Info Disclosure
CVSS 9.8
CVE-2023-3711
MEDIUM
Honeywell PM43 <P10.19.050004 - Session Fixation
CVSS 6.4
CVE-2023-41012
CRITICAL
China Mobile Intelligent Home Gateway v.HG6543C4 - RCE
CVSS 9.8
CVE-2023-4649
MEDIUM
instantsoft/icms2 <2.16.1 - Info Disclosure
CVSS 5.4
CVE-2023-40273
HIGH
Apache Airflow < 2.7.0 - Authenticated Session Fixation via Password Reset
CVSS 8.0
CVE-2023-24477
HIGH
Guardian/CMC <22.6.2 - Privilege Escalation
CVSS 7.0
CVE-2023-21239
MEDIUM
Android - Local Information Disclosure via Notification Image Data Leak
CVSS 5.5
CVE-2023-21238
MEDIUM
Android - Local Information Disclosure via RemoteViews visitUris
CVSS 5.5
CVE-2023-37946
HIGH
Jenkins OpenShift Login Plugin <1.1.0.227.v27e08dfb_1a_20 - Info Di...
CVSS 8.8
CVE-2023-34656
HIGH
Xiamen Si Xin Communication Technology Video <4.1 - Privilege Escal...
CVSS 8.8
CVE-2023-3394
MEDIUM
fossbilling <0.5.1 - Info Disclosure
CVSS 5.4
CVE-2023-34156
MEDIUM
Huawei EMUI - Session Fixation via Early Fingerprint API
CVSS 5.3
CVE-2023-28809
HIGH
Hikvision Access Control Devices - Session Hijacking via Reused Session ID
CVSS 7.5
CVE-2023-3192
MEDIUM
froxlor/froxlor <2.1.0 - Info Disclosure
CVSS 5.4
CVE-2023-32997
HIGH
Jenkins CAS Plugin <1.6.2 - Auth Bypass
CVSS 8.8
CVE-2023-31498
CRITICAL
PHP Gurukul Hospital Management System <4.0 - Privilege Escalation
CVSS 9.8
CVE-2023-28316
CRITICAL
rocket.chat - Session Fixation via 2FA Bypass
CVSS 9.8
CVE-2023-30056
HIGH
FICO Origination Manager Decision Module 4.8.1 - Info Disclosure
CVSS 7.5
CVE-2023-1265
MEDIUM
GitLab <15.9.6-15.11.1 - Info Disclosure
CVSS 5.4
CVE-2023-29020
MEDIUM
fastify/passport < 1.1.0 - Cross-Site Request Forgery Protection Bypass via Session Fixation
CVSS 6.5
Details
Vulnerabilities
404