CWE-613

Insufficient Session Expiration

Parent: CWE-672 - Operation on a Resource after Expiration or Release

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

575 vulnerabilities with CWE-613
CVE-2025-36377 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-36376 MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-27898 MEDIUM
IBM DB2 Recovery Expert 5.5 IF002 - Auth Bypass
CVSS 6.3
CVE-2025-55705 HIGH
Evmapa EV Charging System - Session Management
CVSS 7.3
CVE-2025-36065 MEDIUM
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00-5.2.0.12 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-36063 MEDIUM
IBM Sterling Connect:Express Adapter 5.2.0.00-5.2.0.12 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-52661 LOW
HCL AION 2 - Insufficient Session Expiration
CVSS 2.4
CVE-2025-4677 MEDIUM
ABB WebPro SNMP Card PowerValue <1.1.8.K - Info Disclosure
CVSS 6.5
CVE-2025-31962 LOW
HCL BigFix IVR 4.2 - Insufficient Session Expiration in Web UI Authentication
CVSS 2.0
CVE-2025-68954 MEDIUM
Pterodactyl <1.11.11 - Info Disclosure
CVSS 5.4
CVE-2025-55254 LOW
HCL BigFix Remote Control Lite Web Portal <=10.1.0.0326 - Path-Relative Stylesheet Code Execution
CVSS 3.7
CVE-2025-62329 MEDIUM
HCL DevOps Deploy 8.0.0.0-8.0.1.10 and HCL Launch 7.3.0.0-7.3.2.15 - Insufficient Session Expiration via Race Condition
CVSS 5.0
CVE-2025-36360 MEDIUM
IBM UrbanCode/DevOps Deploy Insufficient Session Expiration via Race Condition
CVSS 5.0
CVE-2025-65430 MEDIUM
allauth < 65.13.0 - Insufficient Session Expiration
CVSS 5.4
CVE-2025-62631 MEDIUM
FortiOS 6.4.0-6.4.15, 7.0.0-7.0.18, 7.2.0-7.2.12, 7.4.0 - Insufficient Session Expiration via SSLVPN
CVSS 5.6
CVE-2025-65883 HIGH
Genexis Platinum 4410 Firmware P4410-V2-1.41 - Remote Code Execution via Stale Session Token Reuse
CVSS 8.4
CVE-2025-11699 HIGH
nopCommerce < 4.70.0 and 4.80.3 - Insufficient Session Expiration
CVSS 7.1
CVE-2025-66289 HIGH
OrangeHRM 5.0-5.7 - Insufficient Session Expiration
CVSS 8.8
CVE-2025-66223 HIGH
OpenObserve <0.16.0 - Privilege Escalation
CVE-2025-53896 HIGH
Kiteworks MFT <9.1.0 - Info Disclosure
CVSS 7.1
CVE-2025-64708 MEDIUM
authentik < 2025.8.5 - Insufficient Session Expiration via Invitation Validation Bypass
CVSS 5.8
CVE-2025-63226 MEDIUM
Sencore SMP100 Firmware V4.2.160, V60.1.4, V60.1.29 - Unauthenticated Session Hijacking via UserManagement.html Endpoint
CVSS 5.7
CVE-2025-56643 CRITICAL
Requarks Wiki.js 2.5.307 - Insufficient Session Expiration via JWT Token Handling
CVSS 9.1
CVE-2025-55278 HIGH
HCL DevOps Loop >=1.0.2 <1.0.2 - Improper Verification of Cryptographic Signature in API Authentication Middleware
CVSS 8.1
CVE-2025-64386 HIGH
Circutor TCPRS1plus >=1.0.14 <1.0.14 - Session Hijacking via JWT Token Reuse
Details
Vulnerabilities 575