Vulnerabilities > Session Fixation

DATE CVE VULNERABILITY TITLE RISK
2022-07-06 CVE-2022-22681 Session Fixation vulnerability in Synology Photo Station
Session fixation vulnerability in access control management in Synology Photo Station before 6.8.16-3506 allows remote attackers to bypass security constraint via unspecified vectors.
network
low complexity
synology CWE-384
5.0
2022-07-01 CVE-2022-25896 Session Fixation vulnerability in Passport Project Passport
This affects the package passport before 0.6.0.
5.8
2022-06-28 CVE-2022-24444 Session Fixation vulnerability in Silverstripe
Silverstripe silverstripe/framework through 4.10 allows Session Fixation.
network
low complexity
silverstripe CWE-384
6.4
2022-05-25 CVE-2022-27305 Session Fixation vulnerability in Gibbonedu Gibbon
Gibbon v23 does not generate a new session ID cookie after a user authenticates, making the application vulnerable to session fixation.
network
gibbonedu CWE-384
6.8
2022-05-24 CVE-2022-1849 Session Fixation vulnerability in Filegator
Session Fixation in GitHub repository filegator/filegator prior to 7.8.0.
network
low complexity
filegator CWE-384
5.5
2022-04-27 CVE-2021-38869 Session Fixation vulnerability in IBM Qradar Security Information and Event Manager
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout.
network
low complexity
ibm CWE-384
7.5
2022-04-14 CVE-2020-25152 Session Fixation vulnerability in Bbraun Datamodule Compactplus and Spacecom
A session fixation vulnerability in the B.
network
bbraun CWE-384
5.8
2022-04-06 CVE-2022-26591 Session Fixation vulnerability in Fantec Mwid25-Ds Firmware 2.000.030
FANTEC GmbH MWiD25-DS Firmware v2.000.030 allows unauthenticated attackers to access and download arbitrary files via a crafted GET request.
network
low complexity
fantec CWE-384
7.5
2022-03-24 CVE-2022-24781 Session Fixation vulnerability in Geon Project Geon 1.0.0
Geon is a board game based on solving questions about the Pythagorean Theorem.
network
low complexity
geon-project CWE-384
5.5
2022-03-09 CVE-2022-24745 Session Fixation vulnerability in Shopware
Shopware is an open commerce platform based on the Symfony php Framework and the Vue javascript framework.
network
shopware CWE-384
5.8