CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
416 vulnerabilities with CWE-384
CVE-2022-24444
MEDIUM
Silverstripe framework <4.10 - Info Disclosure
CVSS 6.5
CVE-2022-27305
HIGH
Gibbon < 23.0.02 - Session Fixation
CVSS 8.8
CVE-2022-1849
MEDIUM
filegator/filegator <7.8.0 - Info Disclosure
CVSS 5.4
CVE-2022-26591
HIGH
MWiD25-DS Firmware <2.000.030 - Info Disclosure
CVSS 7.5
CVE-2022-24781
HIGH
Geon - Session Fixation via UUID Spoofing
CVSS 7.1
CVE-2022-24745
MEDIUM
Shopware < 6.4.8.2 - Session Fixation via HTTP Cache
CVSS 4.8
CVE-2022-22551
HIGH
DELL EMC AppSync <4.3 - Info Disclosure
CVSS 8.3
CVE-2021-32088
CRITICAL
Quest KACE Systems Management Appliance 11.0.273 - Unauthenticated Brute-Force Attack via kboxid Cookie Removal
CVSS 9.8
CVE-2021-3740
MEDIUM
chatwoot < 2.4.0 - Session Fixation via Password Change
CVSS 6.8
CVE-2021-36394
CRITICAL
Moodle - Remote Code Execution in Shibboleth Authentication Plugin
CVSS 9.8
CVE-2021-42761
CRITICAL
FortiWeb 5.9.0-5.9.1, 6.0.0-6.0.7, 6.1.0-6.1.2, 6.2.0-6.2.6, 6.3.0-6.3.16, 6.4 - Unauthenticated Session Fixation
CVSS 9.0
CVE-2021-29368
HIGH
CuppaCMS < 2019-11-12 - Session Fixation
CVSS 8.8
CVE-2021-46279
MEDIUM
Lanner Inc IAC-AST2500A <1.10.0 - Session Fixation
CVSS 5.8
CVE-2021-38869
CRITICAL
IBM QRadar SIEM <7.5 - Info Disclosure
CVSS 9.8
CVE-2021-39066
HIGH
IBM Financial Transaction Manager 3.2.4 - Info Disclosure
CVSS 8.8
CVE-2021-20151
CRITICAL
Trendnet AC2600 TEW-827DRU <2.08B01 - Session Hijacking
CVSS 10.0
CVE-2021-31745
HIGH
Pluck-CMS Pluck <4.7.15 - Session Fixation
CVSS 7.5
CVE-2021-41246
MEDIUM
Express OpenID Connect <2.5.1 - Session Fixation
CVSS 4.6
CVE-2021-41268
MEDIUM
Symfony/SecurityBundle <5.3.12 - Info Disclosure
CVSS 6.5
CVE-2021-42073
HIGH
Barrier < 2.4.0 - Session Fixation via Client Label Spoofing
CVSS 8.2
CVE-2021-41553
CRITICAL
ARCHIBUS Web Central 21.3.3.815 - Info Disclosure
CVSS 9.8
CVE-2021-35948
MEDIUM
ownCloud Server <10.8.0 - Auth Bypass
CVSS 5.4
CVE-2021-22237
MEDIUM
GitLab <13.12.9, <14.0.7, <14.1.2 - Info Disclosure
CVSS 6.6
CVE-2021-39290
CRITICAL
NetModule <4.3.0.113-4.5.0.105 - Limited Session Fixation
CVSS 9.8
CVE-2021-22927
HIGH
Citrix ADC/Gateway <13.0-82.45 - Session Fixation
CVSS 8.1
Details
Vulnerabilities
416