CWE-613— Insufficient Session Expiration
According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."— MITRE CWE catalog
664 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-613page 5 of 14
- CVE-2026-24669HIGHCVSS 7.8EG 7.82026-02-03
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already …
- CVE-2024-36041HIGHCVSS 7.8EG 7.82024-07-05
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1 allows connections via ICE based purely on the host, i.e., all local connections are accepted. This allows another user on the same machine to…
- CVE-2021-25985HIGHCVSS 7.8EG 7.82021-11-16
In Factor (App Framework & Headless CMS) v1.0.4 to v1.8.30, improperly invalidate a user’s session even after the user logs out of the application. In addition, user sessions are stored in the browser’s local storage, which by default …
- CVE-2024-35206HIGHCVSS 7.7EG 7.82024-06-11
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V1.2). The affected application does not expire the session. This could allow an attacker to get unauthorized access.
- CVE-2026-83540HIGHCVSS 7.7EG 7.72026-10-07
When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in us…
- CVE-2025-64386HIGHCVSS 7.7EG 7.72025-10-31
The equipment grants a JWT token for each connection in the timeline, but during an active valid session, a hijacking of the token can be done. This will allow an attacker with the token modify parameters of security, access or even steal …
- CVE-2025-1968HIGHCVSS 7.7EG 7.72025-04-09
Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncommon circumstances allows reusing Session IDs (Session Replay Attacks).This issue affects Sitefinity: from 14.0 through 1…
- CVE-2024-1623HIGHCVSS 7.7EG 7.72024-03-14
Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is poss…
- CVE-2026-87720HIGHCVSS 7.6EG 7.62026-09-24
Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction logic (ProjectCacheImpl) in Gerrit Code Review versions 2.16.0 through 3.12.9, 3.13.0 through 3.13.8, and 3.14.0 through…
- CVE-2024-25628HIGHCVSS 7.6EG 7.62024-02-16
Alf.io is a free and open source event attendance management system. In versions prior to 2.0-M4-2402 users can access the admin area even after being invalidated/deleted. This issue has been addressed in version 2.0-M4-2402. All users are…
- CVE-2013-0335HIGHCVSS 7.6EG 7.62013-03-22
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM that was bound to the same VNC port.
- CVE-2026-100711HIGHCVSS 7.5EG 7.52026-09-26
froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user password is changed. Attackers holding hijacked sessions, valid API keys, or 2FA trust tokens retain full account access…
- CVE-2026-75907HIGHCVSS 7.5EG 7.52026-09-24
The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID stored on an NTAG212 NFC chip. A UID is a manufacturer serial number sent in the clear on every read and is not intended…
- CVE-2026-65984HIGHCVSS 7.5EG 7.52026-08-18
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or groups…
- CVE-2026-44383HIGHCVSS 7.5EG 7.52026-07-10
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.
- CVE-2026-44648HIGHCVSS 7.5EG 7.52026-05-29
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0, SillyTavern relies on cookie-session fo…
- CVE-2026-9096HIGHCVSS 7.5EG 7.52026-05-28
Casdoor versions 2.362.0 and earlier do not enforce SAML assertion time bounds. The gosaml2 library reports all time-validation results, including NotOnOrAfter and NotBefore, in the assertionInfo.WarningInfo field. However, ParseSamlRespon…
- CVE-2026-29092HIGHCVSS 7.5EG 7.52026-03-25
Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway session management allows blocked users to maintain active sessions after their account is disabled. This could allow …
- CVE-2026-27652HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-25778HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-25711HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-20895HIGHCVSS 7.5EG 7.52026-02-27
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same session identifier. This implementation results in predictable session identifiers and enable…
- CVE-2026-25476HIGHCVSS 7.5EG 7.52026-02-25
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0, the session expiration check in `library/auth.inc.php` runs only when `skip_timeout_reset` is not present in t…
- CVE-2026-24894HIGHCVSS 7.5EG 7.52026-02-12
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSION superglobal is not correctly reset between requests. This allows a subsequent request processed by the same worker to…
- CVE-2021-47740HIGHCVSS 7.5EG 7.52025-12-31
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session credentials without proper expiration. Attackers can exploit the weak session handling to maintain unauthorized access a…
- CVE-2022-50692HIGHCVSS 7.5EG 7.52025-12-30
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack activ…
- CVE-2025-28059HIGHCVSS 7.5EG 7.52025-04-18
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, th…
- CVE-2024-39809HIGHCVSS 7.5EG 7.52024-08-14
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
- CVE-2024-0260HIGHCVSS 7.5EG 7.52024-01-07
A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of the component Password Change. The manipulation leads…
- CVE-2023-4320HIGHCVSS 7.5EG 7.52023-12-18
An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attacker who uses this arithmetic overflow to create personal access tokens that are valid indefinitely, resulting in damage …
- CVE-2023-30403HIGHCVSS 7.5EG 7.52023-05-02
An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows attackers to bypass login by connecting to the web app after a successful attempt by a legitimate user.
- CVE-2023-27891HIGHCVSS 7.5EG 7.52023-03-06
rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.15.1, 4.16.1, and 4.17.1.
- CVE-2022-3080HIGHCVSS 7.5EG 7.52022-09-21
By sending specific queries to the resolver, an attacker can cause named to crash.
- CVE-2022-2306HIGHCVSS 7.5EG 7.52022-07-05
Old session tokens can be used to authenticate to the application and send authenticated requests.
- CVE-2022-24341HIGHCVSS 7.5EG 7.52022-02-25
In JetBrains TeamCity before 2021.2.1, editing a user account to change its password didn't terminate sessions of the edited user.
- CVE-2021-45885HIGHCVSS 7.5EG 7.52021-12-29
An issue was discovered in Stormshield Network Security (SNS) 4.2.2 through 4.2.7 (fixed in 4.2.8). Under a specific update-migration scenario, the first SSH password change does not properly clear the old password.
- CVE-2021-33982HIGHCVSS 7.5EG 7.52021-09-08
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3.8.0 and earlier, which allows a remote attacker to reuse, spoof, or steal other user and admin sessions.
- CVE-2021-39113HIGHCVSS 7.5EG 7.52021-08-30
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to continue to view cached content even after losing permissions, via a Broken Access Control vulnerability in the allowlist feature. The affected …
- CVE-2021-35342HIGHCVSS 7.5EG 7.52021-08-27
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing i…
- CVE-2021-37156HIGHCVSS 7.5EG 7.52021-08-05
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor authentication for the user's account, but the intended behavior is for those sessions to be terminated.
- CVE-2021-33322HIGHCVSS 7.5EG 7.52021-08-03
In Liferay Portal 7.3.0 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 18, and 7.2 before fix pack 5, password reset tokens are not invalidated after a user changes their password, which allows remote attackers to…
- CVE-2021-1501HIGHCVSS 7.5EG 7.52021-04-29
A vulnerability in the SIP inspection engine of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause a crash and reload of an affected d…
- CVE-2021-3183HIGHCVSS 7.5EG 7.52021-01-19
Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.
- CVE-2016-20007HIGHCVSS 7.5EG 7.52021-01-01
The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.
- CVE-2020-24713HIGHCVSS 7.5EG 7.52020-10-28
Gophish through 0.10.1 does not invalidate the gophish cookie upon logout.
- CVE-2020-24387HIGHCVSS 7.5EG 7.52020-10-19
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write op…
- CVE-2020-15074HIGHCVSS 7.5EG 7.52020-07-14
OpenVPN Access Server older than version 2.8.4 and version 2.9.5 generates new user authentication tokens instead of reusing exiting tokens on reconnect making it possible to circumvent the initial token expiry timestamp.
- CVE-2020-10876HIGHCVSS 7.5EG 7.52020-05-04
The OKLOK (3.1.1) mobile companion app for Fingerprint Bluetooth Padlock FB50 (2.3) does not correctly implement its timeout on the four-digit verification code that is required for resetting passwords, nor does it properly restrict excess…
- CVE-2016-11058HIGHCVSS 7.5EG 7.52020-04-28
The NETGEAR genie application before 2.4.34 for Android is affected by mishandling of hard-coded API keys and session IDs.
- CVE-2020-8867HIGHCVSS 7.5EG 7.52020-04-22
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of OPC Foundation UA .NET Standard 1.04.358.30. Authentication is not required to exploit this vulnerability. The specific flaw ex…
Map vulnerabilities like CWE-613 to your infrastructure
EchelonGraph correlates every CVE — across CWE-613 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →