Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-613

MITRE ↗

CWE-613

69
CRITICAL
191
HIGH
263
MEDIUM
47
LOW
596 CVEs · Page 7/12
5.3
CVE-2024-23586

HCL Nomad is susceptible to an insufficient session expiration vulnerability.   Under certain circumstances, an unauthen

4.9
CVE-2024-46892

A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not p

4.8
CVE-2024-21492

All versions of the package github.com/greenpau/caddy-security are vulnerable to Insufficient Session Expiration due to

4.7
CVE-2022-38382

IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 d

4.3
CVE-2024-0260

A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected

4.3
CVE-2024-31995

`@digitalbazaar/zcap` provides JavaScript reference implementation for Authorization Capabilities. Prior to version 9.0.

4.3
CVE-2024-29402

cskefu v7 suffers from Insufficient Session Expiration, which allows attackers to exploit the old session for malicious

4.3
CVE-2024-35048

An issue in SurveyKing v1.3.1 allows attackers to execute a session replay attack after a user changes their password.

4.3
CVE-2024-32006

A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2). The affected application

4.3
CVE-2024-35160

IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for Data 7.3, 7.4, 7.5, and 7

4.2
CVE-2024-48926

Umbraco, a free and open source .NET content management system, has an insufficient session expiration issue in versions

4.2
CVE-2024-11668

An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17.5 before 17.5.3, and 17

3.9
CVE-2023-45718

Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persi

3.7
CVE-2024-0942

A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as problematic. Affected i

3.7
CVE-2024-0943

A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic. Affected by this vulnerab

3.7
CVE-2024-0944

A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic. Affected by this issue

3.7
CVE-2022-45862

An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6

3.7
CVE-2024-11208

A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functi

3.7
CVE-2024-12667

A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by this issue is some unkn

3.1
CVE-2024-0350

A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as problematic. Affected by t

3.1
CVE-2024-25619

Mastodon is a free, open-source social network server based on ActivityPub. When an OAuth Application is destroyed, the

3.0
CVE-2024-22403

Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attack

2.6
CVE-2024-7998

In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them usin

9.8
CVE-2023-1788

Insufficient Session Expiration in GitHub repository firefly-iii/firefly-iii prior to 6.

9.8
CVE-2023-35857

In Siren Investigate before 13.2.2, session keys remain active even after logging out.

9.8
CVE-2023-4005

Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.

9.8
CVE-2023-5838

Insufficient Session Expiration in GitHub repository linkstackorg/linkstack prior to v4.2.9.

9.8
CVE-2023-5865

Insufficient Session Expiration in GitHub repository thorsten/phpmyfaq prior to 3.2.2.

9.1
CVE-2023-31065

Insufficient Session Expiration vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLo

8.8
CVE-2022-43844

IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is no

8.8
CVE-2023-23614

Pi-hole®'s Web interface (based off of AdminLTE) provides a central location to manage your Pi-hole. Versions 4.0 and ab

8.8
CVE-2023-24426

Jenkins Azure AD Plugin 303.va_91ef20ee49f and earlier does not invalidate the previous session on login.

8.8
CVE-2023-23929

vantage6 is a privacy preserving federated learning infrastructure for secure insight exchange. Currently, the refresh t

8.8
CVE-2023-1543

Insufficient Session Expiration in GitHub repository answerdev/answer prior to 1.0.6.

8.8
CVE-2023-36252

An issue in Ateme Flamingo XL v.3.6.20 and XS v.3.6.5 allows a remote authenticated attacker to execute arbitrary code a

8.8
CVE-2023-4126

Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.

8.8
CVE-2023-49091

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as

8.8
CVE-2023-46326

ZStack Cloud version 3.10.38 and before allows unauthenticated API access to the list of active job UUIDs and the sessio

8.8
CVE-2023-49935

An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control because of a slurmd Mess

8.8
CVE-2023-51772

One Identity Password Manager before 5.13.1 allows Kiosk Escape. This product enables users to reset their Active Direct

8.2
CVE-2023-5889

Insufficient Session Expiration in GitHub repository pkp/pkp-lib prior to 3.3.0-16.

8.1
CVE-2023-40537

An authenticated user's session cookie may remain valid for a limited time after logging out from the BIG-IP Configurat

8.1
CVE-2023-33303

A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthoriz

7.6
CVE-2023-4320

An arithmetic overflow flaw was found in Satellite when creating a new personal access token. This flaw allows an attack

7.5
CVE-2023-27891

rami.io pretix before 4.17.1 allows OAuth application authorization from a logged-out session. The fixed versions are 4.

7.5
CVE-2023-30403

An issue in the time-based authentication mechanism of Aigital Aigital Wireless-N Repeater Mini_Router v0.131229 allows

7.3
CVE-2023-38489

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6

7.2
CVE-2023-32318

Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextclo

7.2
CVE-2023-37570

This vulnerability exists in ESDS Emagic Data Center Management Suit due to non-expiry of session cookie. By reusing th

7.2
CVE-2023-42768

When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user's rol

Frequently Asked Questions

What is CWE-613?

CWE-613 (CWE-613) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-613?

There are 691 CVE records associated with CWE-613 in our database. Of these, 69 are critical severity, 191 are high severity, and 263 are medium severity.

How can I protect against CWE-613 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-613 using AI-powered security agents.

Detect CWE-613 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-613 vulnerabilities across your infrastructure.

Get Started