Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4,
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level variables rather than in
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissio
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in ser
Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing.This issue affects Per
File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ
Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application i
FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password
Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user logs out. As a result, pre
A vulnerability has been identified in SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Up
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user sessions are not prope
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve
OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41) that allows a local networ
Insufficient Session Expiration vulnerability in Apache Airflow Fab Provider. This issue affects Apache Airflow Fab Pro
Misskey is an open source, federated social media platform. Starting in version 12.109.0 and prior to version 2025.2.0-a
Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a valid session ID and there
Coder allows organizations to provision remote development environments via Terraform. In versions 2.22.0 through 2.24.3
Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep
ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is vulnerable to an insufficient se
The identity infrastructure software ZITADEL offers developers the ability to manage user sessions using the Session API
Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under some specific and uncomm
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system re
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allow
KZTech JT3500V 4G LTE CPE 2.0.1 contains a session management vulnerability that allows attackers to reuse old session c
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in For
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online Library Management Syst
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank Locker Management System v
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM v3.0 allows attackers to
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood Bank & Donor Management Sy
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online Course Registration v3.1 al
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car Rental Project v3.0 allo
CubeCart is an ecommerce software solution. Prior to version 6.5.11, there is an absence of automatic session expiration
Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout or session termination
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation.This issue affects Site
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel Pro: through 1.0.1.
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could allow an authenticated p
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex
Frequently Asked Questions
What is CWE-613?
CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-613?
There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.
How can I protect against CWE-613 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.
Detect CWE-613 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.
Get Started