CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2022-36437
CRITICAL
Hazelcast < 3.12.13 and Hazelcast Jet < 4.5.4 - Unauthenticated Session Fixation
CVSS 9.1
CVE-2022-44017
HIGH
Simmeth Lieferantenmanager <5.6 - Privilege Escalation
CVSS 7.5
CVE-2022-38628
MEDIUM
Nortek Linear eMerge E3-Series <0.32-09a - XSS
CVSS 6.1
CVE-2022-4231
MEDIUM
Tribal Systems Zenario CMS 9.3.57595 - Session Fixation
CVSS 4.2
CVE-2022-44788
MEDIUM
Appalti & Contratti 9.12.2 - Session Fixation
CVSS 6.5
CVE-2022-44007
HIGH
BACKCLICK Professional <5.9.63 - Privilege Escalation
CVSS 8.8
CVE-2022-30769
MEDIUM
ZoneMinder <1.36.12 - Info Disclosure
CVSS 4.6
CVE-2022-43687
MEDIUM
Concrete CMS <8.5.10, 9.0.0-9.1.2 - Info Disclosure
CVSS 5.4
CVE-2022-31689
CRITICAL
VMware Workspace ONE Assist <22.10 - Privilege Escalation
CVSS 9.8
CVE-2022-43398
HIGH
POWER METER SICAM Q100 < V2.50 - Info Disclosure
CVSS 7.5
CVE-2022-40293
CRITICAL
Phppointofsale PHP Point Of Sale - Session Fixation
CVSS 9.8
CVE-2022-40226
HIGH
SICAM P850 <V3.10 - Info Disclosure
CVSS 7.5
CVE-2022-34334
MEDIUM
IBM Sterling Partner Engagement Manager 2.0 - Privilege Escalation
CVSS 6.5
CVE-2022-40630
MEDIUM
Tacitine Firewall <22.20.1 - Session Fixation
CVSS 6.5
CVE-2022-3269
CRITICAL
ikus060/rdiffweb <2.4.7 - Info Disclosure
CVSS 9.8
CVE-2022-38369
HIGH
Apache IoTDB 0.13.0 - Session Fixation
CVSS 8.8
CVE-2022-38054
CRITICAL
Apache Airflow <2.3.3 - Info Disclosure
CVSS 9.8
CVE-2022-31798
MEDIUM
Nortek Linear eMerge E3-Series < 0.32-07p - Cross-Site Scripting and Session Fixation via CardFormatNo Parameter
CVSS 6.1
CVE-2022-2997
HIGH
GitHub snipe/snipe-it <6.0.10 - Info Disclosure
CVSS 8.0
CVE-2022-30605
HIGH
WWBN AVideo 11.6 and dev master commit 3f7c0364 - Session Fixation via Crafted HTTP Request
CVSS 8.8
CVE-2022-2820
HIGH
GitHub repository namelessmc/nameless <v2.0.2 - Info Disclosure
CVSS 7.0
CVE-2022-33927
MEDIUM
Dell Wyse Management Suite <3.6.1 - Session Fixation
CVSS 5.4
CVE-2022-34536
HIGH
Digital Watchdog DW MEGApix IP Cameras - Session Hijacking via Crafted Session Token
CVSS 7.5
CVE-2022-22681
HIGH
Synology Photo Station <6.8.16-3506 - Auth Bypass
CVSS 8.1
CVE-2022-25896
MEDIUM
passport < 0.6.0 - Session Fixation via Session Regeneration
CVSS 4.8
Details
Vulnerabilities
416