VulnSea

CWE-613

CVEs classified under CWE-613, newest first.

90 CVEsRSS

CVE-2026-55617Medium· 6.9
1w ago

Hydro is a next-generation high-performance online judge platform

Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic in packages/hydrooj/src/service/layers/base.ts creates a replacement session token without deleting the previous tok…

▾ Sunlithydro-dev · HydroEPSS 0.47%via NVD
CVE-2026-56665Medium· 4.2
2w ago

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider

▾ Sunlitzitadel · github.com/zitadel/zitadelEPSS 0.27%via OSV
CVE-2026-81268High· 8.1
2w ago

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.

▾ Twilightlangflow · langflowEPSS 0.43%via NVD
CVE-2026-80174Medium· 5.3
2w ago

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability

Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Session Expiration vulnerability. A low privileged attacker with remote access could potentially expl…

▾ SunlitDell · Secure Connect Gateway 5.0 - ApplicationEPSS 0.27%via CVEORG
CVE-2026-87014Medium· 6.5PoC
2w ago

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role synchronization in backend/open_webui/routers/auths.py and backend/open_webui/utils/oauth.py updated an administrator's d…

▾ Twilightopenwebui · open_webuiEPSS 0.51%via NVD
CVE-2026-55250High· 8.7
2w ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless token validation engines and high-perf…

▾ Twilightmacropay-solutions · maravel-frameworkEPSS 0.87%via NVD
CVE-2026-19931Critical· 9.8PoC⚖ disputed
3w ago

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previo…

▾ Abyssalhaxx · curlEPSS 0.75%via NVD
CVE-2026-86215Medium· 4.3PoC
3w ago

A vulnerability was identified in Mstfakts College-Management-System

A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_out leads to sessio…

▾ TwilightMstfakts · College-Management-SystemEPSS 0.36%via NVD
CVE-2026-61608Medium· 6.8
3w ago

SolidInvoice is an open-source invoicing platform

SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid indefinitely, meaning a leaked, forwarded, or archived invitatio…

▾ SunlitEPSS 0.32%via NVD
CVE-2026-55513Medium· 5.4PoC
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the nebula-mgmt Web UI host-creation path ignores both the server-wide enrollment_token_ttl security setting and per-networ…

▾ Twilightforgekeep · nebula-meshEPSS 0.32%via NVD
CVE-2026-53602Medium
3w ago

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN

nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization gaps let a host that should no longer be trusted obtain a fresh, valid Nebula certificate, because nebula-mgmt does n…

▾ Sunlitforgekeep · github.com/forgekeep/nebula-meshEPSS 0.31%via NVD
CVE-2026-84480Critical· 9.8
3w ago

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any t…

▾ MidnightEPSS 0.51%via NVD
CVE-2026-84203High· 8.1
3w ago

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access

Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their password, allowing attackers to maintain account access. An attacker with a stolen refresh token can call the RefreshToken RPC to obtain new acc…

▾ TwilightEPSS 0.45%via NVD
CVE-2026-82469Medium· 5.4
4w ago

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT access tokens without requiring a refresh token. Attackers can present an access token to the refresh route via non-POST m…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-79664High· 7.4
1mo ago

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft

Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option, allowing attackers to maintain perpetual authenticated access after token theft. Three independent revocation mechanisms fail: logout panics on ni…

▾ Twilightlin-snow · github.com/lin-snow/ech0EPSS 0.27%via NVD
CVE-2026-65984High· 7.5
1mo ago

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls back from current user data to decoded.groups, including when the user is deleted or grou…

▾ Twilightfrangoteam · FUXAEPSS 0.52%via NVD
CVE-2026-45791Medium· 5.9
1mo ago

Dokploy is a free, self-hostable Platform as a Service (PaaS)

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/user.ts updates account.password without deleting other rows from session, allowing a comp…

▾ SunlitEPSS 0.41%via NVD
CVE-2026-73611Medium· 6.8
1mo ago

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrat…

▾ SunlitEPSS 0.43%via NVD
CVE-2026-66376Medium· 4.2
1mo ago

Credentials for a deleted user may remain valid for a short period under specific conditions.

Credentials for a deleted user may remain valid for a short period under specific conditions.

▾ SunlitEPSS 0.22%via NVD
CVE-2026-17600High· 8.8
1mo ago

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed

Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke their cached permissions when that user's account was deleted, deactivated, or had its password changed. A user whose account was already l…

▾ Twilightsonatype · nexus_repository_managerEPSS 0.25%via NVD
CVE-2026-48079High· 7.4
1mo ago

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navigates to the `/logout` page, the page's server-side load handler deletes the `access_toke…

▾ TwilightEPSS 0.50%via NVD
CVE-2026-39924Medium· 6.8
1mo ago

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full account access after a victim changes their password, because the access_tokens table is nev…

▾ SunlitFlarum · Flarum FrameworkEPSS 0.37%via NVD
CVE-2026-71206High· 8.3PoC
1mo ago

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database

Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature and returns the embedded claims.Account object unmodified, never re-fetching the account from the database. No session store or token-revocat…

▾ MidnightEPSS 0.37%via NVD
CVE-2026-14227Medium· 4.9
1mo ago

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Session Expiration vulnerability. This could allow active sessions to retain their previous permission set after inactivit…

▾ SunlitEPSS 0.38%via NVD
CVE-2026-43983High
2mo ago

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions

▾ Twilightpocket-id · github.com/pocket-id/pocket-id/backendEPSS 0.36%via GHSA
CVE-2026-59219High· 7.1
2mo ago

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout

▾ Twilightopen-webui · open-webuiEPSS 0.46%via GHSA
CVE-2026-56750Critical
2mo ago

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

▾ Midnightgitea · code.gitea.io/giteaEPSS 0.48%via GHSA
CVE-2026-16206Medium· 6.3
2mo ago

A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0

A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue affects the function _load_id_token of the file oauth2_provider/oauth2_validators.py. The manipulation leads to session expiration. The att…

▾ SunlitEPSS 0.37%via NVD
CVE-2026-63089Critical· 9.3
2mo ago

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a…

WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows unauthenticated network attackers to recover WireGuard peer credentials by brute-forcing a…

▾ MidnightEPSS 0.41%via NVD
CVE-2026-44383High· 7.5
2mo ago

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

Multiple connections to the backend using the same charging station ID are allowed, which could allow an attacker to deploy multiple instances of malicious OCPP clients to overwhelm the backend.

▾ TwilightEPSS 0.56%via NVD
CWE-613 vulnerabilities (CVEs) — page 2 · VulnSea