CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
509 vulnerabilities with CWE-613
CVE-2025-4528
MEDIUM
Digitro Ngc Explorer < 3.44.15 - Insufficient Session Expiration
CVSS 4.3
CVE-2025-46336
MEDIUM
Rack::Session <2.1.1 - Privilege Escalation
CVSS 4.2
CVE-2025-32441
MEDIUM
Rack < 2.2.14 - Race Condition
CVSS 4.2
CVE-2025-46815
HIGH
ZITADEL <3.0.0-2.70.10 - DoS
CVSS 8.0
CVE-2025-46344
MEDIUM
Auth0 Next.js SDK <4.5.1 - Info Disclosure
CVE-2025-2185
HIGH
ALBEDO Telecom Net.Time - PTP/NTP clock <1.4.4 - Info Disclosure
CVSS 8.0
CVE-2025-42602
HIGH
Meon KYC - Auth Bypass
CVE-2025-28059
HIGH
Nagios Network Analyzer - Insufficient Session Expiration
CVSS 7.5
CVE-2025-24859
HIGH
Apache Roller <6.1.5 - Info Disclosure
CVSS 8.8
CVE-2025-30516
LOW
Mattermost Mobile Apps <=2.25.0 - Info Disclosure
CVSS 2.0
CVE-2025-1968
HIGH
Progress Software Corporation Sitefinity <15.2 - Info Disclosure
CVSS 7.7
CVE-2025-28132
MEDIUM
Nagios Network Analyzer - Insufficient Session Expiration
CVSS 4.6
CVE-2025-2596
MEDIUM
Checkmk < 2.1.0 - Insufficient Session Expiration
CVSS 5.3
CVE-2025-1198
MEDIUM
Gitlab < 17.6.5 - Insufficient Session Expiration
CVSS 4.2
CVE-2025-24973
CRITICAL
Concorde <12.25Q1.1 - Info Disclosure
CVSS 9.3
CVE-2025-24896
HIGH
Misskey <2025.2.0-alpha.0 - Info Disclosure
CVSS 8.1
CVE-2025-22386
HIGH
Optimizely Configured Commerce - Insufficient Session Expiration
CVSS 7.3
CVE-2024-43181
MEDIUM
IBM Concert <2.1.0 - Privilege Escalation
CVSS 6.3
CVE-2024-13996
CRITICAL
Nagios XI < 2024 - Insufficient Session Expiration
CVSS 9.8
CVE-2024-33507
HIGH
Fortinet Fortiisolator < 2.4.5 - Insufficient Session Expiration
CVSS 7.4
CVE-2024-41985
LOW
Siemens Opcenter Quality - Insufficient Session Expiration
CVSS 2.6
CVE-2024-27779
MEDIUM
FortiSandbox <4.4.4 - Info Disclosure
CVSS 6.7
CVE-2024-50562
MEDIUM
Fortinet Fortisase < 7.2.11 - Insufficient Session Expiration
CVSS 4.8
CVE-2024-22351
MEDIUM
IBM InfoSphere Information 11.7 - Privilege Escalation
CVSS 6.3
CVE-2024-45651
MEDIUM
IBM Sterling Connect Direct Web Services - Insufficient Session Exp...
CVSS 6.3
Details
Vulnerabilities
509