Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-50339 Session Fixation vulnerability in Glpi-Project Glpi
GLPI is a free asset and IT management software package.
network
low complexity
glpi-project CWE-384
5.3
2024-11-12 CVE-2023-50176 Session Fixation vulnerability in Fortinet Fortios
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.
network
low complexity
fortinet CWE-384
8.8
2024-11-06 CVE-2024-10318 Session Fixation vulnerability in F5 products
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time.
network
low complexity
f5 CWE-384
5.4
2024-10-22 CVE-2024-48929 Session Fixation vulnerability in Umbraco CMS
Umbraco is a free and open source .NET content management system.
network
high complexity
umbraco CWE-384
4.2
2024-10-19 CVE-2024-10158 Session Fixation vulnerability in PHPgurukul Boat Booking System 1.0
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0.
network
low complexity
phpgurukul CWE-384
8.8
2024-09-27 CVE-2024-8643 Session Fixation vulnerability in Oceanicsoft Valeapp
Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking.This issue affects ValeApp: before v2.0.0.
network
low complexity
oceanicsoft CWE-384
critical
9.8
2024-09-10 CVE-2024-42345 Session Fixation vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2).
network
low complexity
siemens CWE-384
4.3
2024-09-09 CVE-2024-7341 Session Fixation vulnerability in Redhat Keycloak
A session fixation issue was discovered in the SAML adapters provided by Keycloak.
network
high complexity
redhat CWE-384
7.1
2024-08-12 CVE-2023-38018 Session Fixation vulnerability in IBM Aspera Shares 1.10.0
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could allow an authenticated user to impersonate another user on the system.
network
low complexity
ibm CWE-384
5.4
2024-03-11 CVE-2024-28197 Session Fixation vulnerability in Zitadel
Zitadel is an open source identity management system.
high complexity
zitadel CWE-384
7.5