Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-613

MITRE ↗

CWE-613

69
CRITICAL
191
HIGH
263
MEDIUM
47
LOW
596 CVEs · Page 4/12
CVE-2026-45757

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,

CVE-2026-49277

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,

CVE-2026-43918

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/

CVE-2026-63175

PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in

CVE-2026-17600

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio

CVE-2026-65984

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in ser

CVE-2026-75554

Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from

CVE-2026-77130

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control

CVE-2026-81826

Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m

9.8
CVE-2024-13280

Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per

9.8
CVE-2025-53826

File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ

9.8
CVE-2025-59841

Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i

9.8
CVE-2025-54592

FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during

9.8
CVE-2024-13996

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password

9.3
CVE-2025-24973

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1

9.1
CVE-2025-56643

Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre

8.8
CVE-2024-45386

A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up

8.8
CVE-2025-24859

A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not prope

8.8
CVE-2025-40566

A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve

8.8
CVE-2025-66289

OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i

8.4
CVE-2025-65883

A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ

8.1
CVE-2024-45033

Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro

8.1
CVE-2025-24896

Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-a

8.1
CVE-2021-47663

Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and there

8.1
CVE-2025-58437

Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3

8.1
CVE-2025-55278

Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep

8.0
CVE-2025-2185

ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se

8.0
CVE-2025-46815

The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API

7.7
CVE-2025-1968

Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncomm

7.5
CVE-2025-28059

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system re

7.5
CVE-2022-50692

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allow

7.5
CVE-2021-47740

KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session c

7.4
CVE-2024-33507

An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For

7.3
CVE-2025-22386

An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the

7.1
CVE-2025-31952

HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless

7.1
CVE-2025-50488

Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst

7.1
CVE-2025-50491

Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v

7.1
CVE-2025-50484

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to

7.1
CVE-2025-50487

Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy

7.1
CVE-2025-50485

Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al

7.1
CVE-2025-50486

Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo

7.1
CVE-2025-59335

CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration

7.1
CVE-2025-53896

Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus

7.1
CVE-2025-11699

nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination

6.8
CVE-2024-11627

: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site

6.7
CVE-2025-4407

Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.

6.7
CVE-2024-27779

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version

6.6
CVE-2024-25051

IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p

6.5
CVE-2025-36040

IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client

6.5
CVE-2025-58352

Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex

Frequently Asked Questions

What is CWE-613?

CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-613?

There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.

How can I protect against CWE-613 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.

Detect CWE-613 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.

Get Started