CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2021-1501
HIGH
Cisco Firepower/ASA DoS via SIP Pinhole Connection Hash Lookup
CVSS 8.6
CVE-2021-31408
MEDIUM
Vaadin Flow 5.0.0-5.9.9 and Vaadin 19.0.0-19.0.3 - Insufficient Session Expiration via Authentication.logout() Helper
CVSS 6.3
CVE-2021-3144
CRITICAL
SaltStack Salt < 2015.8.10 - Insufficient Session Expiration
CVSS 9.1
CVE-2021-27351
MEDIUM
Telegram <7.2.1-2.4.7 - Info Disclosure
CVSS 5.3
CVE-2021-21032
MEDIUM
Magento <2.4.1, <2.4.0-p1, <2.3.6 - Info Disclosure
CVSS 5.6
CVE-2021-21031
MEDIUM
Magento <2.4.1-2.3.6 - Info Disclosure
CVSS 5.6
CVE-2021-26921
MEDIUM
Argo CD < 1.7.12 - Insufficient Session Expiration
CVSS 6.5
CVE-2021-3311
CRITICAL
October < 1.0.471 - Insufficient Session Expiration via Session Reactivation
CVSS 9.8
CVE-2021-3183
HIGH
Files.com Fat Client 3.3.6 - Insufficient Session Expiration
CVSS 7.5
CVE-2020-4914
MEDIUM
IBM Cloud Pak System 2.3.3.0-2.3.3.5 - Insufficient Session Expiration
CVSS 4.2
CVE-2020-27416
CRITICAL
Mahavitaran Android <7.50 - Privilege Escalation
CVSS 9.8
CVE-2020-29012
MEDIUM
FortiSandbox < 3.2.2 - Insufficient Session Expiration
CVSS 5.6
CVE-2020-10709
HIGH
Ansible Tower < 3.5.6 - Insufficient Session Expiration via OAuth2 Token
CVSS 7.1
CVE-2020-35358
CRITICAL
DomainMOD 4.15.0 - Insufficient Session Expiration
CVSS 9.8
CVE-2020-4995
MEDIUM
IBM Security Identity Governance and Intelligence 5.2.6 - Insufficient Session Expiration
CVSS 5.3
CVE-2020-6649
CRITICAL
FortiIsolator < 2.0.1 - Insufficient Session Expiration
CVSS 9.8
CVE-2020-14247
MEDIUM
HCL OneTest Performance V9.5 V10.0 V10.1 - Insufficient Session Expiration
CVSS 6.5
CVE-2020-15220
MEDIUM
Combodo iTop <2.7.2, 3.0.0 - Info Disclosure
CVSS 6.1
CVE-2020-15218
MEDIUM
Combodo iTop <2.7.2, 3.0.0 - Info Disclosure
CVSS 6.8
CVE-2020-29667
CRITICAL
Lan ATMService M3 ATM Monitoring System 6.1.0 - Info Disclosure
CVSS 9.8
CVE-2020-4696
MEDIUM
IBM Cloud Pak for Security 1.3.0.1 - Insufficient Session Expiration
CVSS 4.3
CVE-2020-13353
LOW
Gitaly 1.79.0-13.3.9 - Insufficient Session Expiration via URL Repository Import
CVSS 2.5
CVE-2020-27422
CRITICAL
Anuko Time Tracker <1.19.23.5311 - Info Disclosure
CVSS 9.8
CVE-2020-23140
HIGH
Microweber 1.1.18 - Info Disclosure
CVSS 8.1
CVE-2020-23136
MEDIUM
Microweber v1.1.18 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities
576