All vulnerabilities
495 / 495
Sort
5.4
CVE-2018-17199AST
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time …
2018-01-01Pre-auth
EPSS20.0%
pct 97
9.8
CVE-2014-2595CVE
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentica…
2014-01-01Pre-auth
EPSS16.5%
pct 96
7.5
CVE-2023-30403CVE
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini…
2023-01-01Pre-auth
EPSS14.9%
pct 96
9.8
CVE-2020-27422CVE
In Anuko Time Tracker v1.19.23.5311, the password reset link emailed to the user doesn't expire…
2020-01-01Pre-auth
EPSS7.8%
pct 93
5.8
CVE-2014-3616DEB
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_k…
2014-01-01
EPSS5.7%
pct 91
7.4
CVE-2021-3144DEB
In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be…
2021-01-01Pre-auth
EPSS5.2%
pct 91
9.8
CVE-2021-24019CVE
An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 an…
2021-01-01Pre-auth
EPSS3.8%
pct 88
9.8
CVE-2020-8234CVE
A vulnerability exists in The EdgeMax EdgeSwitch firmware <v1.9.1 where the EdgeSwitch legacy w…
2020-01-01Pre-auth
EPSS3.4%
pct 87
9.8
CVE-2020-29667CVE
In Lan ATMService M3 ATM Monitoring System 6.1.0, a remote attacker able to use a default cooki…
2020-01-01Pre-auth
EPSS3.2%
pct 86
9.8
CVE-2016-6545CVE
Session cookies are not used for maintaining valid sessions in iTrack Easy. The user's password…
2016-01-01Pre-auth
EPSS3.1%
pct 85
9.8
CVE-2021-3311CVE
An issue was discovered in October through build 471. It reactivates an old session ID (which h…
2021-01-01Pre-auth
EPSS2.9%
pct 85
8.8
CVE-2017-6529CVE
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacki…
2017-01-01Pre-auth
EPSS2.9%
pct 85
8.8
CVE-2024-48827CVE
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and es…
2024-01-01
EPSS2.7%
pct 84
6.5
CVE-2020-9482CVE
If NiFi Registry 0.1.0 to 0.5.0 uses an authentication mechanism other than PKI, when the user …
2020-01-01Pre-auth
EPSS2.6%
pct 83
9.8
CVE-2018-21018DEB
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
2018-01-01Pre-auth
EPSS2.6%
pct 83
9.8
CVE-2016-11014CVE
NETGEAR JNR1010 devices before 1.0.0.32 have Incorrect Access Control because the ok value of t…
2016-01-01Pre-auth
EPSS2.5%
pct 82
8.8
CVE-2019-5462DEB
A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens a…
2019-01-01Pre-auth
EPSS2.5%
pct 82
4.0
CVE-2013-2059DEB
OpenStack Identity (Keystone) Folsom 2012.2.4 and earlier, Grizzly before 2013.1.1, and Havana …
2013-01-01
EPSS2.5%
pct 82
9.8
CVE-2021-25981CVE
In Talkyard, regular versions v0.2021.20 through v0.2021.33 and dev versions v0.2021.20 through…
2021-01-01Pre-auth
EPSS2.5%
pct 82
9.8
CVE-2020-35358CVE
DomainMOD domainmod-v4.15.0 is affected by an insufficient session expiration vulnerability. On…
2020-01-01Pre-auth
EPSS2.4%
pct 82
5.4
CVE-2017-12159DEB
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each sessio…
2017-01-01Pre-auth
EPSS2.4%
pct 81
8.8
CVE-2019-7280CVE
Prima Systems FlexAir, Versions 2.3.38 and prior. The session-ID is of an insufficient length a…
2019-01-01
EPSS2.4%
pct 81
8.1
CVE-2016-0721DEB
Session fixation vulnerability in pcsd in pcs before 0.9.157.
2016-01-01Pre-auth
EPSS2.3%
pct 80
9.8
CVE-2019-8149CVE
Insecure authentication and session management vulnerability exists in Magento 2.2 prior to 2.2…
2019-01-01Pre-auth
EPSS2.1%
pct 79
5.0
CVE-2019-1003049DEB
Users who cached their CLI authentication before Jenkins was updated to 2.150.2 and newer, or 2…
2019-01-01
EPSS2.1%
pct 79
2.6
CVE-2013-2104DEB
python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly c…
2013-01-01
EPSS2.1%
pct 78
8.8
CVE-2017-15653CVE
Improper administrator IP validation after his login in the HTTPd server in all current version…
2017-01-01
EPSS2.0%
pct 78
8.8
CVE-2020-12690DEB
An issue was discovered in OpenStack Keystone before 15.0.1, and 16.0.0. The list of roles prov…
2020-01-01
EPSS1.9%
pct 76
4.0
CVE-2013-4222DEB
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 …
2013-01-01
EPSS1.9%
pct 76
4.0
CVE-2012-4413DEB
OpenStack Keystone 2012.1.3 does not invalidate existing tokens when granting or revoking roles…
2012-01-01
EPSS1.9%
pct 76
8.8
CVE-2019-12421CVE
When using an authentication mechanism other than PKI, when the user clicks Log Out in NiFi ver…
2019-01-01
EPSS1.8%
pct 76
9.8
CVE-2020-27739DEB
A Weak Session Management vulnerability in Citadel WebCit through 926 allows unauthenticated re…
2020-01-01Pre-auth
EPSS1.8%
pct 75
4.7
CVE-2021-35214CVE
The vulnerability in SolarWinds Pingdom can be described as a failure to invalidate user sessio…
2021-01-01
EPSS1.8%
pct 75
7.5
CVE-2021-39113CVE
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to …
2021-01-01Pre-auth
EPSS1.8%
pct 74
5.8
CVE-2015-3982DEB
The session.flush function in the cached_db backend in Django 1.8.x before 1.8.2 does not prope…
2015-01-01
EPSS1.7%
pct 74
4.0
CVE-2014-2062DEB
Jenkins before 1.551 and LTS before 1.532.2 does not invalidate the API token when a user is de…
2014-01-01
EPSS1.7%
pct 74
5.6
CVE-2021-21031CVE
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) do not ade…
2021-01-01Pre-auth
EPSS1.7%
pct 73
8.1
CVE-2021-34739CVE
A vulnerability in the web-based management interface of multiple Cisco Small Business Series S…
2021-01-01Pre-auth
EPSS1.6%
pct 72
5.9
CVE-2018-11386AST
An issue was discovered in the HttpFoundation component in Symfony 2.7.x before 2.7.48, 2.8.x b…
2018-01-01Pre-auth
EPSS1.6%
pct 72
9.8
CVE-2020-27416CVE
Mahavitaran android application 7.50 and prior are affected by account takeover due to improper…
2020-01-01Pre-auth
EPSS1.6%
pct 72
Select a vulnerability on the left to open the preview.