CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
575 vulnerabilities with CWE-613
CVE-2025-36377
MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-36376
MEDIUM
IBM Security QRadar EDR 3.12-3.12.23 - Auth Bypass
CVSS 6.3
CVE-2025-27898
MEDIUM
IBM DB2 Recovery Expert 5.5 IF002 - Auth Bypass
CVSS 6.3
CVE-2025-55705
HIGH
Evmapa EV Charging System - Session Management
CVSS 7.3
CVE-2025-36065
MEDIUM
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00-5.2.0.12 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-36063
MEDIUM
IBM Sterling Connect:Express Adapter 5.2.0.00-5.2.0.12 - Insufficient Session Expiration
CVSS 6.3
CVE-2025-52661
LOW
HCL AION 2 - Insufficient Session Expiration
CVSS 2.4
CVE-2025-4677
MEDIUM
ABB WebPro SNMP Card PowerValue <1.1.8.K - Info Disclosure
CVSS 6.5
CVE-2025-31962
LOW
HCL BigFix IVR 4.2 - Insufficient Session Expiration in Web UI Authentication
CVSS 2.0
CVE-2025-68954
MEDIUM
Pterodactyl <1.11.11 - Info Disclosure
CVSS 5.4
CVE-2025-55254
LOW
HCL BigFix Remote Control Lite Web Portal <=10.1.0.0326 - Path-Relative Stylesheet Code Execution
CVSS 3.7
CVE-2025-62329
MEDIUM
HCL DevOps Deploy 8.0.0.0-8.0.1.10 and HCL Launch 7.3.0.0-7.3.2.15 - Insufficient Session Expiration via Race Condition
CVSS 5.0
CVE-2025-36360
MEDIUM
IBM UrbanCode/DevOps Deploy Insufficient Session Expiration via Race Condition
CVSS 5.0
CVE-2025-65430
MEDIUM
allauth < 65.13.0 - Insufficient Session Expiration
CVSS 5.4
CVE-2025-62631
MEDIUM
FortiOS 6.4.0-6.4.15, 7.0.0-7.0.18, 7.2.0-7.2.12, 7.4.0 - Insufficient Session Expiration via SSLVPN
CVSS 5.6
CVE-2025-65883
HIGH
Genexis Platinum 4410 Firmware P4410-V2-1.41 - Remote Code Execution via Stale Session Token Reuse
CVSS 8.4
CVE-2025-11699
HIGH
nopCommerce < 4.70.0 and 4.80.3 - Insufficient Session Expiration
CVSS 7.1
CVE-2025-66289
HIGH
OrangeHRM 5.0-5.7 - Insufficient Session Expiration
CVSS 8.8
CVE-2025-66223
HIGH
OpenObserve <0.16.0 - Privilege Escalation
CVE-2025-53896
HIGH
Kiteworks MFT <9.1.0 - Info Disclosure
CVSS 7.1
CVE-2025-64708
MEDIUM
authentik < 2025.8.5 - Insufficient Session Expiration via Invitation Validation Bypass
CVSS 5.8
CVE-2025-63226
MEDIUM
Sencore SMP100 Firmware V4.2.160, V60.1.4, V60.1.29 - Unauthenticated Session Hijacking via UserManagement.html Endpoint
CVSS 5.7
CVE-2025-56643
CRITICAL
Requarks Wiki.js 2.5.307 - Insufficient Session Expiration via JWT Token Handling
CVSS 9.1
CVE-2025-55278
HIGH
HCL DevOps Loop >=1.0.2 <1.0.2 - Improper Verification of Cryptographic Signature in API Authentication Middleware
CVSS 8.1
CVE-2025-64386
HIGH
Circutor TCPRS1plus >=1.0.14 <1.0.14 - Session Hijacking via JWT Token Reuse
Details
Vulnerabilities
575