CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2025-50491
HIGH
PHPGurukul Bank Locker Management System <v1 - Session Hijacking
CVSS 7.1
CVE-2025-50488
HIGH
PHPGurukul Online Library Management System <3.0 - Session Hijacking
CVSS 7.1
CVE-2025-31952
HIGH
HCL iAutomate - Insufficient Session Expiration
CVSS 7.1
CVE-2025-53826
CRITICAL
File Browser <2.39.0 - Info Disclosure
CVSS 9.8
CVE-2025-53642
MEDIUM
haxcms-nodejs and haxcms-php < 11.0.6 - Insufficient Session Expiration
CVSS 4.8
CVE-2025-4407
MEDIUM
ABB Lite Panel Pro <1.0.1 - Info Disclosure
CVSS 6.7
CVE-2025-49152
HIGH
Microsens NMP Web+ < Version 3.2.5 - Insufficient Session Expiration via Non-Expiring JWT
CVE-2025-4754
LOW
ash_authentication_phoenix < 2.10.0 - Insufficient Session Expiration in Controller
CVE-2025-25019
MEDIUM
IBM QRadar Suite Software <1.11.2.0 - Info Disclosure
CVSS 4.8
CVE-2025-33005
MEDIUM
IBM Planning Analytics Local <2.1 - Privilege Escalation
CVSS 6.3
CVE-2025-48929
MEDIUM
TeleMessage < 2025-05-05 - Insufficient Session Expiration
CVSS 4.0
CVE-2025-48061
MEDIUM
wire-webapp < 2025-05-20-production.0 - Insufficient Session Expiration
CVSS 5.6
CVE-2025-0138
LOW
Palo Alto Networks Prisma Cloud Compute - Info Disclosure
CVE-2025-40566
HIGH
SIMATIC PCS neo < V4.1 Update 3 and < V5.0 Update 1 - Insufficient Session Expiration
CVSS 8.8
CVE-2025-46741
MEDIUM
SEL Blueframe OS < 1.12.0 - Insufficient Session Expiration
CVSS 5.7
CVE-2025-4528
MEDIUM
Dgitro NGC Explorer < 3.44.15 - Insufficient Session Expiration
CVSS 4.3
CVE-2025-46336
MEDIUM
Rack::Session <2.1.1 - Privilege Escalation
CVSS 4.2
CVE-2025-32441
MEDIUM
Rack < 2.2.14 - Unauthenticated Session Restoration via Race Condition in Rack::Session::Pool
CVSS 4.2
CVE-2025-46815
HIGH
ZITADEL < 2.70.10 and 2.71.x < 2.71.9 and 3.0.0-rc.1-3.0.0 - Session Hijacking via IdP Intent Reuse
CVSS 8.0
CVE-2025-46344
MEDIUM
Auth0 Next.js SDK <4.5.1 - Info Disclosure
CVE-2025-2185
HIGH
ALBEDO Telecom Net.Time - PTP/NTP clock <1.4.4 - Info Disclosure
CVSS 8.0
CVE-2025-42602
HIGH
Meon KYC solutions - Session Fixation via API Token Handling
CVE-2025-28059
HIGH
Nagios Network Analyzer 2024R1.0.3 - Insufficient Session Expiration
CVSS 7.5
CVE-2025-24859
HIGH
Apache Roller <6.1.5 - Info Disclosure
CVSS 8.8
CVE-2025-30516
LOW
Mattermost Mobile Apps <=2.25.0 - Info Disclosure
CVSS 2.0
Details
Vulnerabilities
576