V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
Filters

All vulnerabilities

393 / 393
CWE: CWE-384×Clear all
9.8
CVE-2018-11714CVE
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58…
2018-01-01Pre-auth
EPSS36.5%
pct 98
9.8
CVE-2018-18925CVE
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as…
2018-01-01Pre-auth
EPSS31.9%
pct 98
7.5
CVE-2019-12258CVE
Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET s…
2019-01-01Pre-auth
EPSS23.4%
pct 97
5.4
CVE-2018-17199AST
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time …
2018-01-01Pre-auth
EPSS20.0%
pct 97
9.3
CVE-2024-50339ANC
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to…
2024-01-01Pre-auth
EPSS19.8%
pct 97
8.8
CVE-2019-10008CVE
Zoho ManageEngine ServiceDesk 9.3 allows session hijacking and privilege escalation because an …
2019-01-01
EPSS19.7%
pct 97
9.8
CVE-2017-12965CVE
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sess…
2017-01-01Pre-auth
EPSS15.7%
pct 96
2.6
CVE-2013-2249DEB
mod_session_dbd.c in the mod_session_dbd module in the Apache HTTP Server before 2.4.5 proceeds…
2013-01-01
EPSS14.3%
pct 96
9.8
CVE-2025-52689
Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain …
2025-01-01Pre-auth
EPSS11.0%
pct 95
7.5
CVE-2019-17563DEB
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0…
2019-01-01Pre-auth
EPSS10.7%
pct 95
4.3
CVE-2014-0033DEB
org/apache/catalina/connector/CoyoteAdapter.java in Apache Tomcat 6.0.33 through 6.0.37 does no…
2014-01-01
EPSS9.9%
pct 94
8.1
CVE-2017-6412CVE
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.
2017-01-01Pre-auth
EPSS7.5%
pct 93
2.6
CVE-2013-2067DEB
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication featur…
2013-01-01
EPSS7.1%
pct 93
9.8
CVE-2021-36394DEB
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
2021-01-01Pre-auth
EPSS7.0%
pct 93
5.3
CVE-2017-5656CVE
Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are as…
2017-01-01Pre-auth
EPSS6.8%
pct 93
6.1
CVE-2022-31798CVE
Nortek Linear eMerge E3-Series 0.32-07p devices are vulnerable to /card_scan.php?CardFormatNo= …
2022-01-01Pre-auth
EPSS6.4%
pct 92
8.1
CVE-2017-12619CVE
Apache Zeppelin prior to 0.7.3 was vulnerable to session fixation which allowed an attacker to …
2017-01-01Pre-auth
EPSS4.9%
pct 91
9.8
CVE-2015-1820DEB
REST client for Ruby (aka rest-client) before 1.8.0 allows remote attackers to conduct session …
2015-01-01Pre-auth
EPSS4.3%
pct 89
8.8
CVE-2018-5385CVE
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a …
2018-01-01Pre-auth
EPSS4.2%
pct 89
9.8
CVE-2019-18418CVE
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via ch…
2019-01-01Pre-auth
EPSS4.0%
pct 89
8.8
CVE-2022-30605CVE
A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6…
2022-01-01Pre-auth
EPSS3.9%
pct 88
7.5
CVE-2020-5645CVE
Session fixation vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT…
2020-01-01Pre-auth
EPSS3.8%
pct 88
9.3
CVE-2007-4188CVE
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers t…
2007-01-01
EPSS3.8%
pct 88
8.1
CVE-2017-14263CVE
Honeywell NVR devices allow remote attackers to create a user account in the admin group by lev…
2017-01-01Pre-auth
EPSS3.7%
pct 88
6.5
CVE-2018-0229CVE
A vulnerability in the implementation of Security Assertion Markup Language (SAML) Single Sign-…
2018-01-01Pre-auth
EPSS3.7%
pct 88
5.8
CVE-2011-4718DEB
Session fixation vulnerability in the Sessions subsystem in PHP before 5.5.2 allows remote atta…
2011-01-01
EPSS3.6%
pct 87
9.8
CVE-2019-5523CVE
VMware vCloud Director for Service Providers 9.5.x prior to 9.5.0.3 update resolves a Remote Se…
2019-01-01Pre-auth
EPSS3.3%
pct 86
6.5
CVE-1999-0428CVE
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
1999-01-01Pre-auth
EPSS3.2%
pct 86
9.8
CVE-2018-18926DEB
Gitea before 1.5.4 allows remote code execution because it does not properly validate session I…
2018-01-01Pre-auth
EPSS3.0%
pct 85
9.8
CVE-2015-1174CVE
Session fixation vulnerability in Unit4 Polska TETA Web (formerly TETA Galactica) 22.62.3.4 and…
2015-01-01Pre-auth
EPSS2.9%
pct 85
5.8
CVE-2008-3222DEB
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed mo…
2008-01-01
EPSS2.9%
pct 85
8.1
CVE-2019-11213CVE
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session toke…
2019-01-01Pre-auth
EPSS2.8%
pct 84
7.5
CVE-2020-5654CVE
Session fixation vulnerability in TCP/IP function included in the firmware of MELSEC iQ-R serie…
2020-01-01Pre-auth
EPSS2.7%
pct 83
9.8
CVE-2016-9125CVE
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session ident…
2016-01-01Pre-auth
EPSS2.7%
pct 83
8.1
CVE-2019-11331CVE
Network Time Protocol (NTP), as specified in RFC 5905, uses port 123 even for modes where a fix…
2019-01-01Pre-auth
EPSS2.6%
pct 83
6.4
CVE-2013-4213DEB
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocatio…
2013-01-01
EPSS2.5%
pct 82
6.4
CVE-2013-4128DEB
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocatio…
2013-01-01
EPSS2.4%
pct 82
8.1
CVE-2016-0721DEB
Session fixation vulnerability in pcsd in pcs before 0.9.157.
2016-01-01Pre-auth
EPSS2.3%
pct 80
8.8
CVE-2020-15909CVE
SolarWinds N-central through 2020.1 allows session hijacking and requires user interaction or p…
2020-01-01Pre-auth
EPSS2.2%
pct 80
9.8
CVE-2020-5543CVE
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmw…
2020-01-01Pre-auth
EPSS2.1%
pct 79
Select a vulnerability on the left to open the preview.