Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-384

MITRE ↗

CWE-384

10
CRITICAL
11
HIGH
25
MEDIUM
1
LOW
51 CVEs · Page 1/2
9.9
CVE-2026-18527

IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker t

9.8
CVE-2026-23796

Quick.Cart allows a user's session identifier to be set before authentication. The value of this session ID stays the sa

9.8
CVE-2026-24352

PluXml CMS allows a user's session identifier to be set before authentication. The value of this session ID stays the sa

9.8
CVE-2026-25101

Bludit allows user's session identifier to be set before authentication. The value of this session ID stays the same aft

9.8
CVE-2025-67446

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u

9.8
CVE-2021-32088

An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-

9.6
CVE-2026-33757

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for

9.1
CVE-2025-69602

A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th

9.1
CVE-2026-40010

Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a sessi

9.1
CVE-2009-10007

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst

8.9
CVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful t

8.8
CVE-2026-41613

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

8.8
CVE-2026-56425

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat

8.2
CVE-2025-71057

Improper session management in D-Link Wireless N 300 ADSL2+ Modem Router DSL-124 ME_1.00 allows attackers to execute a s

8.1
CVE-2026-30808

Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777

7.6
CVE-2026-13707

Session fixation vulnerability in Wikimedia Foundation OAuth. This vulnerability is associated with program files src/

7.5
CVE-2026-24894

FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO

7.5
CVE-2026-31940

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled

7.5
CVE-2026-12581

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s

7.3
CVE-2026-2177

A vulnerability has been found in SourceCodester Prison Management System 1.0. The impacted element is an unknown functi

7.3
CVE-2026-33492

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function

6.8
CVE-2026-48545

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Spa

6.7
CVE-2026-70594

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions

6.5
CVE-2026-45773

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-

6.5
CVE-2026-43827

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0

6.5
CVE-2026-69245

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of

6.3
CVE-2025-36115

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0.00 through 5.2.0.12 does not disallow the session

6.3
CVE-2026-11335

A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae

6.2
CVE-2025-46605

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 cont

5.9
CVE-2025-55266

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carr

5.9
CVE-2026-33946

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby S

5.7
CVE-2025-7015

Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi

5.7
CVE-2025-7014

Session Fixation vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Session Hijacking. This issue affect

5.6
CVE-2026-14609

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue

5.4
CVE-2026-30224

OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r

5.4
CVE-2025-65415

docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the applic

5.4
CVE-2026-40082

Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen

5.4
CVE-2026-56224

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica

5.4
CVE-2026-16089

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 aut

5.3
CVE-2020-36913

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predef

4.8
CVE-2025-70973

ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated

4.7
CVE-2026-59883

Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar

4.3
CVE-2025-68139

EVerest is an EV charging software stack. In all versions up to and including 2025.12.1, the default value for `terminat

4.3
CVE-2026-23624

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.

4.3
CVE-2026-53900

Firefox for iOS preserved cookies set on the initial PDF request across cross-origin HTTP redirects in TemporaryDocument

4.2
CVE-2026-41839

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab

3.5
CVE-2026-34454

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p

CVE-2026-22082

This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the u

CVE-2026-33384

QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same

CVE-2026-35095

KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid

Frequently Asked Questions

What is CWE-384?

CWE-384 (CWE-384) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-384?

There are 55 CVE records associated with CWE-384 in our database. Of these, 10 are critical severity, 11 are high severity, and 25 are medium severity.

How can I protect against CWE-384 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-384 using AI-powered security agents.

Detect CWE-384 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-384 vulnerabilities across your infrastructure.

Get Started