CWE-384 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-384 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
CVE-2026-86688Session Fixation vulnerability in team-alembic ash_authentication allows an attacker who can plant a…0.7%높음7.4CVE-2026-95828A vulnerability was determined in Mstfakts College-Management-System. This affects the function sess…0.5%낮음2.1CVE-2026-77614Opencast is a free, open-source platform to support the management of educational audio and video co…0.4%높음8.8CVE-2026-92609Session fixation in HTTP management authentication allows remote attackers to gain unauthorized acce…0.4%심각9.8CVE-2026-61592djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered pe…0.3%높음7.4CVE-2026-82355When a request to the Airflow core API carries both a session cookie and an explicit `Authorization:…0.3%보통4.2CVE-2026-71302The application accepts user-supplied session identifiers and does not regenerate the session ID aft…0.3%높음7.5CVE-2026-64857tirreno, a security framework, has a session fixation issue in versions prior to 0.10.0. During auth…0.3%보통5.3
전체 목록
22건
CVE-2026-79312webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly f…0.3%보통6.8
CVE-2026-81181SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication fl…0.3%낮음3.7
CVE-2026-69214Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The CookieJar client middleware…0.3%보통6.8
CVE-2026-92984HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables instead of coo…0.3%높음8.5
CVE-2026-1758Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation. This issue a…0.2%높음8.3
CVE-2026-78428For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user recei…0.2%높음8.0
CVE-2026-85238MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow.…0.2%높음7.6
CVE-2026-86279A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0…0.2%낮음2.1
CVE-2026-86674A vulnerability was found in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02e…0.2%낮음2.1
CVE-2026-104469YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack authenticated s…0.2%높음7.6
CVE-2026-76196Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An…0.2%높음7.4
CVE-2026-101268If an attacker is able to convince a victim on a specially crafted link, the victim is logged in to the attack…0.2%낮음1.7
CVE-2026-61687Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to …0.2%높음7.1
CVE-2026-57179Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipe…0.2%보통4.2
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.