The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to
Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstati
listmonk is a standalone, self-hosted, newsletter and mailing list manager. From version 4.1.0 to before version 6.1.0,
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that a
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redi
Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0
Manyfold is an open source, self-hosted web application for managing a collection of 3d models, particularly focused on
Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign auth
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when t
A flaw was found in Keycloak. When revokeRefreshToken=true is enabled and persistent session storage is in use, a server
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid sess
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configure
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP Card PowerValue UL.Thi
NocoDB is software for building databases as spreadsheets. Prior to version 0.301.3, the password reset flow did not rev
Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.7.2, password reset tokens in
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, Vikunja's link share authentication (Get
blueprintUE is a tool to help Unreal Engine developers. Prior to 4.2.0, when a user changes their password via the profi
libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked lo
OpenClaw before 2026.4.24 contains a token revocation vulnerability allowing callers with revoked slash tokens to contin
OpenClaw before 2026.4.22 contains a webhook secret revocation bypass vulnerability allowing callers with old Slack and
A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate ses
IBM Sterling Connect:Express Adapter for Sterling B2B Integrator 5.2.0 5.2.0.00 through 5.2.0.12 does not invalidate ses
IBM Concert 1.0.0 through 2.1.0 does not invalidate session after logout which could allow an authenticated user to impe
IBM DB2 Recovery Expert for LUW 5.5 Interim Fix 002 does not invalidate session after a timeout which could allow an aut
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an
IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after privileges have been mod
IBM Aspera Shares 1.9.9 through 1.11.0 does not invalidate session after a password reset which could allow an authentic
A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the
A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope
A vulnerability was identified in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is a
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,
Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does no
Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This fail
An issue that could prevent session inactivity timeouts from triggering due to automatic page reloading has been resolve
CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1,
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started