CWE-613
Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."
576 vulnerabilities with CWE-613
CVE-2025-1968
HIGH
Progress Software Corporation Sitefinity <15.2 - Info Disclosure
CVSS 7.7
CVE-2025-28132
MEDIUM
Nagios Network Analyzer 2024R1.0.3 - Insufficient Session Expiration
CVSS 4.6
CVE-2025-2596
MEDIUM
Checkmk <2.3.0p30, <2.2.0p41, 2.1.0p49 - Insufficient Session Expiration
CVSS 5.3
CVE-2025-1198
MEDIUM
GitLab 16.11-17.6.4, 17.7-17.7.3, 17.8-17.8.1 - Insufficient Session Expiration via ActionCable
CVSS 4.2
CVE-2025-24973
CRITICAL
Concorde <12.25Q1.1 - Info Disclosure
CVSS 9.3
CVE-2025-24896
HIGH
Misskey <2025.2.0-alpha.0 - Info Disclosure
CVSS 8.1
CVE-2025-22386
HIGH
Optimizely Configured Commerce < 5.2.2408 - Insufficient Session Expiration
CVSS 7.3
CVE-2024-40683
MEDIUM
IBM Operations Analytics - Log Analysis is affected by a TOCTOU weakness allowing active sessions to persist beyond a password change
CVSS 6.3
CVE-2024-43181
MEDIUM
IBM Concert <2.1.0 - Privilege Escalation
CVSS 6.3
CVE-2024-13996
CRITICAL
Nagios XI < 2024R1.1.3 - Insufficient Session Expiration
CVSS 9.8
CVE-2024-33507
HIGH
FortiIsolator 2.0-2.4.4 - Insufficient Session Expiration and Incorrect Authorization via Crafted Cookie
CVSS 7.4
CVE-2024-41985
LOW
Siemens Opcenter Quality SmartClient Modules - Insufficient Session Expiration
CVSS 2.6
CVE-2024-27779
MEDIUM
FortiSandbox <4.4.4 - Info Disclosure
CVSS 6.7
CVE-2024-50562
MEDIUM
Fortinet Fortisase < 7.2.11 - Insufficient Session Expiration
CVSS 4.8
CVE-2024-22351
MEDIUM
IBM InfoSphere Information 11.7 - Privilege Escalation
CVSS 6.3
CVE-2024-45651
MEDIUM
IBM Sterling Connect:Direct Web Services 6.1.0-6.1.0.28 - Insufficient Session Expiration
CVSS 6.3
CVE-2024-49825
MEDIUM
IBM Robotic Process Automation <21.0.7.20,23.0.20 - Privilege Escal...
CVSS 6.3
CVE-2024-25051
MEDIUM
IBM Jazz Reporting Service 7.0.2-7.0.3 - Privilege Escalation
CVSS 6.6
CVE-2024-57056
MEDIUM
WombatDialer <25.02 - Info Disclosure
CVSS 5.4
CVE-2024-45386
HIGH
SIMATIC PCS neo, SIMOCODE ES, SIRIUS Safety ES, SIRIUS Soft Starter...
CVSS 8.8
CVE-2024-13280
CRITICAL
Drupal Persistent Login <2.2.2 - Info Disclosure
CVSS 9.8
CVE-2024-45033
HIGH
Apache Airflow Fab Provider <1.5.2 - Info Disclosure
CVSS 8.1
CVE-2024-11627
MEDIUM
Progress Sitefinity 4.0-15.2.8421 Session Fixation via Insufficient Session Expiration
CVSS 6.8
CVE-2024-56413
MEDIUM
Acronis Cyber Protect <16 - Info Disclosure
CVSS 6.1
CVE-2024-56351
MEDIUM
JetBrains TeamCity < 2024.12 - Insufficient Session Expiration
CVSS 6.3
Details
Vulnerabilities
576