Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to incorrect management of s
Tattile Smart+, Vega, and Basic device families firmware versions 1.181.5 and prior implement an authentication token (X
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing multiple session cookies to
Insufficient Session Expiration vulnerability in hexpm hexpm/hexpm ('Elixir.Hexpm.Accounts.PasswordReset' module) allows
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper Ke
Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authe
An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session aft
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows allows Reusing Session ID
WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation
Vikunja is an open-source self-hosted task management platform. Prior to version 2.0.0, the application allows users to
When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-s
Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by
Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Admin
Fleet is open source device management software. Prior to 4.81.0, a vulnerability in Fleet’s password management logic c
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
pyLoad is a free and open-source download manager written in Python. Versions up to and including 0.5.0b3.dev97 cache `r
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions
OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device session
Actual is a local-first personal finance app. Prior to 26.6.0, in OpenID multi-user mode, disabling a user only blocks f
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.
Initiative is a self-hosted project management platform. Versions of the application prior to 0.32.4 do not invalidate p
OpenClaw before 2026.3.28 fails to disconnect active WebSocket sessions when devices are removed or tokens are revoked.
Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, admin
Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens aft
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstatio
FrankenPHP is a modern application server for PHP. Prior to 1.11.2, when running FrankenPHP in worker mode, the $_SESSIO
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio
SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode
Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to de
Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2
ZITADEL is an open source identity management platform. Prior to 3.4.8 and 4.12.2, a potential vulnerability exists in Z
Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers with a previously obta
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication
OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintai
This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 163 CVE records associated with CWE-613 in our database. Of these, 14 are critical severity, 47 are high severity, and 72 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started