CWE-613: CWE-613

143
Total CVEs
33
Critical
63
High
7.5
Avg CVSS

Yearly Trend

2026
16
2025
48
2024
28
2023
15
2022
10

Top Affected Vendors

1 Ibm 10
2 Fortinet 8
3 Apache 6
4 Hcltech 4
5 Siemens 3
6 Nagios 3
7 F5 2
8 Cisco 2
9 Dell 2
10 Phpgurukul 2

All CWE-613 CVEs (143)

CVE-2025-43819
6.5

This vulnerability allows remote unauthenticated attackers to reuse expired user sessions through the Single Logout (SLO) API in affected Liferay vers...

Sep 24, 2025
CVE-2024-55603
6.5

This vulnerability allows attackers to use expired session IDs to maintain unauthorized access to Kanboard instances. It affects all Kanboard users ru...

Dec 19, 2024
CVE-2024-36523
6.5

An access control vulnerability in Wvp GB28181 Pro 2.0 allows users to maintain access to application data after their accounts (including administrat...

Jun 12, 2024
CVE-2025-36376
6.3

IBM Security QRadar EDR versions 3.12 through 3.12.23 fail to properly invalidate sessions after expiration, allowing authenticated users to impersona...

Feb 17, 2026
CVE-2024-43181
6.3

IBM Concert versions 1.0.0 through 2.1.0 fail to properly invalidate user sessions after logout, allowing authenticated users to reuse old session tok...

Feb 4, 2026
CVE-2025-36065
6.3

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator versions 5.2.0.00 through 5.2.0.12 fails to properly invalidate user sessions when a ...

Jan 20, 2026
CVE-2025-36063
6.3

IBM Sterling Connect:Express Adapter for Sterling B2B Integrator fails to properly invalidate user sessions after logout, allowing authenticated users...

Jan 20, 2026
CVE-2024-22351
6.3

IBM InfoSphere Information Server 11.7 fails to properly invalidate user sessions after logout, allowing authenticated users to reuse old session toke...

Apr 23, 2025
CVE-2024-45651
6.3

IBM Sterling Connect:Direct Web Services versions 6.1.0, 6.2.0, and 6.3.0 fail to properly invalidate user sessions when a browser is closed. This all...

Apr 18, 2025
CVE-2024-56351
6.3

This vulnerability in JetBrains TeamCity allows access tokens to remain valid after user roles are removed, potentially enabling unauthorized access. ...

Dec 20, 2024
CVE-2024-52311
6.3

This vulnerability in data.all's AWS Cognito integration allows authentication tokens to remain valid after user logout, enabling continued access to ...

Nov 9, 2024
CVE-2024-45462
6.3

This CVE describes a session expiration vulnerability in Apache CloudStack's web interface where logout doesn't properly invalidate user sessions. An ...

Oct 16, 2024
CVE-2023-40695
6.3

IBM Cognos Controller versions 10.4.1, 10.4.2, and 11.0.0 fail to properly invalidate user sessions after logout, allowing an authenticated attacker t...

May 3, 2024
CVE-2024-56413
6.1

CVE-2024-56413 is an improper session management vulnerability in Acronis Cyber Protect 16 for Windows where user sessions remain active after account...

Jan 2, 2025
CVE-2025-64708
5.8

This vulnerability in authentik allows expired invitations to remain valid for up to 5 minutes or longer during system backlog, potentially enabling u...

Nov 19, 2025
CVE-2025-63226
5.7

This vulnerability allows attackers on the same network as a logged-in user to hijack their session and add unauthorized administrative accounts to th...

Nov 18, 2025
CVE-2025-62631
5.6

This CVE describes an insufficient session expiration vulnerability in Fortinet FortiOS where active SSLVPN sessions are not terminated after a user's...

Dec 9, 2025
CVE-2025-48061
5.6

A session invalidation vulnerability in Wire webapp allows users who logged out to be automatically logged back in when reopening the application. Thi...

May 22, 2025
CVE-2023-26288
5.5

IBM Aspera Orchestrator 4.0.1 fails to invalidate user sessions after password changes, allowing authenticated users to maintain access with old crede...

Jul 30, 2024
CVE-2025-68954
5.4

This vulnerability in Pterodactyl allows users who were actively connected via SFTP to retain file access even after their permissions are revoked. It...

Jan 6, 2026
CVE-2025-65430
5.4

This vulnerability in django-allauth allows users whose accounts have been deactivated (is_active=False) to continue using previously issued access an...

Dec 15, 2025
CVE-2025-12110
5.4

This Keycloak vulnerability allows offline sessions to remain valid even after administrators remove the offline_access scope from clients. Attackers ...

Oct 23, 2025
CVE-2025-11429
5.4

Keycloak sessions created while 'Remember Me' was enabled retain extended lifetimes even after administrators disable this setting at the realm level....

Oct 23, 2025
CVE-2025-10223
5.4

This vulnerability allows authenticated attackers (local or remote) to maintain access to the AxxonSoft Axxon One Web Admin Panel even after their pri...

Sep 10, 2025
CVE-2024-57056
5.4

WombatDialer versions before 25.02 incorrectly handle cookie sessions, writing full session identities to system logs. This allows attackers who can a...

Feb 18, 2025
CVE-2025-2596
5.3

This vulnerability in Checkmk allows attackers to bypass session logout mechanisms, potentially maintaining unauthorized access to monitoring systems....

Mar 26, 2025
CVE-2024-25954
5.3

Dell PowerScale OneFS versions 9.5.0.x through 9.7.0.x have an insufficient session expiration vulnerability that allows remote unauthenticated attack...

Mar 28, 2024
CVE-2026-24667
5.0

Open eClass platform versions before 4.2 fail to invalidate active user sessions after password changes, allowing existing session tokens to remain va...

Feb 3, 2026
CVE-2025-62329
5.0

HCL DevOps Deploy/Launch has a race condition in HTTP session IP binding that may allow brief session reuse from a new IP address before invalidation....

Dec 16, 2025
CVE-2025-36360
5.0

This CVE describes a race condition vulnerability in IBM UrbanCode Deploy and DevOps Deploy where HTTP session client-IP binding enforcement can be by...

Dec 15, 2025
CVE-2025-62781
5.0

This vulnerability allows attackers with stolen session tokens to maintain access to PILOS accounts even after users change their passwords. It affect...

Oct 27, 2025
CVE-2025-35433
5.0

CVE-2025-35433 is an authentication bypass vulnerability in CISA Thorium where previously used tokens remain valid after password resets. This allows ...

Sep 17, 2025
CVE-2024-46892
4.9

This vulnerability allows authenticated attackers to maintain active sessions even after their user accounts have been disabled or deleted in SINEC IN...

Nov 12, 2024
CVE-2025-25252
4.8

This vulnerability allows attackers with access to SAML session records to re-open terminated sessions, potentially regaining access to FortiOS SSL VP...

Oct 14, 2025
CVE-2025-53642
4.8

This vulnerability in HAXcms backends fails to properly terminate user sessions during logout, allowing attackers to maintain access to authenticated ...

Jul 11, 2025
CVE-2024-50562
4.8

This vulnerability allows attackers who have obtained SSL-VPN session cookies to reuse them even after sessions have expired or been logged out. It af...

Jun 10, 2025
CVE-2022-38382
4.7

This vulnerability allows authenticated users to access sensitive information from other users' sessions after they have logged out. It affects IBM Cl...

Aug 13, 2024
CVE-2025-28132
4.6

A session management vulnerability in Nagios Network Analyzer allows attackers to reuse session tokens after users log out, enabling unauthorized acce...

Apr 1, 2025
CVE-2025-4528
4.3

This vulnerability in DΓ­gitro NGC Explorer allows attackers to remotely trigger session expiration, potentially causing service disruption. It affect...

May 11, 2025
CVE-2024-48926
4.2

Umbraco CMS has an insufficient session expiration vulnerability where the logout page displays a session timeout message approximately 30 seconds bef...

Oct 22, 2024
CVE-2025-52661
2.4

HCL AION version 2 has JWT tokens that remain valid for an excessively long time, allowing attackers who obtain these tokens to potentially maintain u...

Jan 19, 2026
CVE-2025-31962
2.0

This vulnerability allows authenticated attackers to maintain unauthorized access to protected API endpoints in HCL BigFix IVR due to insufficient ses...

Jan 7, 2026
CVE-2026-1842
N/A

HyperCloud versions 2.3.5 through 2.6.8 have an authentication flaw where refresh tokens can be used directly for resource access instead of just obta...

Feb 20, 2026

About CWE-613 (CWE-613)

Our database tracks 143 CVEs classified as CWE-613, with 33 rated critical and 63 rated high severity. The average CVSS score for CWE-613 vulnerabilities is 7.5.

External reference: View CWE-613 on MITRE CWE →

Monitor CWE-613 Vulnerabilities

Get alerted when new CWE-613 CVEs affect your infrastructure.

Start Monitoring Free