Vulnerabilities > Insufficient Session Expiration

DATE CVE VULNERABILITY TITLE RISK
2025-05-11 CVE-2025-4528 A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic.
network
low complexity
CWE-613
4.3
2025-04-24 CVE-2021-47663 Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and therefore impersonate a user to gain full access.
network
high complexity
CWE-613
8.1
2025-04-23 CVE-2024-22351 IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
CWE-613
6.3
2025-04-18 CVE-2024-45651 IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0 does not invalidate session after a browser closure which could allow an authenticated user to impersonate another user on the system.
network
low complexity
CWE-613
6.3
2025-04-14 CVE-2024-49825 IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system.
network
low complexity
CWE-613
6.3
2025-04-02 CVE-2024-25051 IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated privileged user to impersonate another user on the system.
network
high complexity
CWE-613
6.6
2025-02-11 CVE-2025-24896 Insufficient Session Expiration vulnerability in Misskey
Misskey is an open source, federated social media platform.
network
low complexity
misskey CWE-613
8.1
2025-02-11 CVE-2024-45386 A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SIMOCODE ES V19 (All versions < V19 Update 1), SIRIUS Safety ES V19 (TIA Portal) (All versions < V19 Update 1), SIRIUS Soft Starter ES V19 (TIA Portal) (All versions < V19 Update 1), TIA Administrator (All versions < V3.0.4).
network
low complexity
CWE-613
8.8
2024-12-20 CVE-2024-56351 Insufficient Session Expiration vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
network
low complexity
jetbrains CWE-613
8.8
2024-12-19 CVE-2024-55603 Insufficient Session Expiration vulnerability in Kanboard
Kanboard is project management software that focuses on the Kanban methodology.
network
low complexity
kanboard CWE-613
6.5