Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow attacker to access to a s
Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP co
OliveTin gives access to predefined shell commands from a web interface. Prior to version 3000.11.1, OliveTin does not r
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function i
A flaw was found in Red Hat Quay. When Red Hat Quay requests password re-verification for sensitive operations, such as
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.9.6, 18.10 before 18.10.4, and
OpenClaw before 2026.3.31 fails to terminate active WebSocket sessions when rotating device tokens. Attackers with previ
A vulnerability exists in SenseLive X3050’s web management interface due to improper session lifetime enforcement, allo
OpenClaw before 2026.4.8 contains an authentication state management vulnerability where the resolvedAuth closure become
OpenClaw before 2026.4.8 contains a session management vulnerability where existing WebSocket sessions survive shared ga
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their a
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.11.7, Cache Mid
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote
The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2,
When internal roles are removed from a user within the WSO2 product, the system fails to invalidate any previously issue
Kiteworks is a private data network (PDN). Prior to version 9.2.1, a vulnerability in Kiteworks Email Protection Gateway
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi
Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh
Packistry is a self-hosted Composer repository designed to handle PHP package distribution. Prior to version 0.13.0, Rep
Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are
An improper session timeout issue in Fortra's GoAnywhere MFT prior to version 7.10.0 results in SAML configured Web User
Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL's external JWT Identity Prov
ZITADEL is an open source identity management platform. Prior to 3.4.12 and 4.15.2, ZITADEL is an open source identity m
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality which is ineffective. Sto
Credentials for a deleted user may remain valid for a short period under specific conditions.
An insufficient session expiration vulnerability exists in the latest version of parisneo/lollms. The application fails
OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. A regression introduced in 7.11.0 p
A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unkno
HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of unauthorized access, session h
IBM Guardium Data Protection 12.0, 12.1, and 12.2 is vulnerable to Security Misconfiguration vulnerability in the user a
ColdFusion is affected by an Insufficient Session Expiration vulnerability that could result in a Security feature bypas
HCL AION version 2 is affected by a JWT Token Expiry Too Long vulnerability. This may increase the risk of token misuse,
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens associated with impersonated
Insufficient session expiration in the Web UI authentication component in HCL BigFix IVR version 4.2 allows an authentic
HyperCloud versions 2.3.5 through 2.6.8 improperly allowed refresh tokens to be used directly for resource access and fa
The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Pr
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorizati
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se
NocoDB is software for building databases as spreadsheets. Prior to 2026.04.4, deleted API tokens continued to authentic
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, revokeAllOAuthTokensByUser in the users s
NocoDB is software for building databases as spreadsheets. Prior to 2026.05.1, a stolen refresh token survived a passwor
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started