Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2024-02-07 CVE-2024-24823 Session Fixation vulnerability in Graylog
Graylog is a free and open log management platform.
network
high complexity
graylog CWE-384
4.4
2024-02-02 CVE-2023-50941 Session Fixation vulnerability in IBM Powersc 1.3/2.0/2.1
IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an authenticated user to gain access to an unauthorized user using session fixation.
network
low complexity
ibm CWE-384
5.4
2024-01-21 CVE-2023-52353 Session Fixation vulnerability in ARM Mbed TLS
An issue was discovered in Mbed TLS through 3.5.1.
network
low complexity
arm CWE-384
7.5
2024-01-19 CVE-2024-23679 Session Fixation vulnerability in Enonic XP
Enonic XP versions less than 7.7.4 are vulnerable to a session fixation issue.
network
low complexity
enonic CWE-384
critical
9.8
2024-01-12 CVE-2023-50920 Session Fixation vulnerability in Gl-Inet products
An issue was discovered on GL.iNet devices before version 4.5.0.
local
low complexity
gl-inet CWE-384
5.5
2024-01-09 CVE-2024-0351 Session Fixation vulnerability in Engineers Online Portal Project Engineers Online Portal 1.0
A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0.
network
low complexity
engineers-online-portal-project CWE-384
3.5
2023-12-19 CVE-2023-6913 Session Fixation vulnerability in Imoulife Imou Life 6.7.0
A session hijacking vulnerability has been detected in the Imou Life application affecting version 6.7.0.
network
low complexity
imoulife CWE-384
8.1
2023-12-11 CVE-2023-49804 Session Fixation vulnerability in multiple products
Uptime Kuma is an easy-to-use self-hosted monitoring tool.
local
low complexity
dockge-kuma uptime-kuma CWE-384
7.8
2023-12-08 CVE-2023-48929 Session Fixation vulnerability in Franklin-Electric System Sentinel Anyware 1.6.24.492
Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation.
network
low complexity
franklin-electric CWE-384
critical
9.8
2023-11-10 CVE-2023-46733 Session Fixation vulnerability in Sensiolabs Symfony
Symfony is a PHP framework for web and console applications and a set of reusable PHP components.
network
low complexity
sensiolabs CWE-384
6.5