$_SecureScope악용 확인 · 악용 확률 · 한국어 권고
CVE Ledger

CWE-613 관련 취약점

같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.

원장 17,280건이 중 악용 확인 1,734건분류: CWE-613

전체 목록

44건

CVE-2026-86698Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organ…0.4%낮음2.3
CVE-2026-79313webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session management relie…0.4%심각9.8
CVE-2026-92976A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.…0.4%보통5.1
CVE-2026-75907The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-…0.4%높음7.5
CVE-2026-88262Insufficient session expiration vulnerability in bizwell xClick allows Authentication Bypass. This issue affec…0.3%높음8.7
CVE-2026-97056SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when configured to use the opaque session tok…0.4%높음7.6
CVE-2026-92616FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-pri…0.3%높음7.6
CVE-2026-81268IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain …0.3%높음8.1
CVE-2026-92358A flaw was found in the first broker login flow of Keycloak. When a user confirms an account-linking request f…0.3%보통6.4
CVE-2026-87014Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1,…0.3%보통6.5
CVE-2026-55617Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recrea…0.3%보통6.9
CVE-2026-100502Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allow…0.3%보통5.9
CVE-2026-79317A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cooki…0.3%보통4.8
CVE-2026-82566The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication sta…0.3%높음8.7
CVE-2026-103283Ghost versions 6.20.0 before 6.57.1 contain a session handling vulnerability that allows authenticated staff u…0.3%높음8.6
CVE-2026-92800Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at paren…0.2%높음7.6
CVE-2026-100711froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies whe…0.3%높음8.7
CVE-2026-104468YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows attackers to reuse …0.3%보통6.3
CVE-2026-88805Incorrect credential cleaning on logout could be used by remote attackers to keep access credentials even afte…0.3%높음8.1
CVE-2026-87720Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache …0.3%높음7.6
CVE-2026-97212The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple end…0.2%보통6.9
CVE-2026-61608SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no e…0.2%보통6.8
CVE-2026-77519MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authenticati…0.2%보통5.4
CVE-2026-85387Concrete CMS before 9.5.4 re-authorized OAuth REST API requests from the bearer token alone and did not re-che…0.2%낮음2.0
CVE-2026-100624Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build/upload/:jobId …0.2%보통5.3
CVE-2026-100554OpenClaw (npm package 'openclaw') versions >= 2026.5.12 and < 2026.8.1 do not immediately invalidate Canvas HT…0.2%낮음2.3
CVE-2026-86215A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown funct…0.2%낮음2.1
CVE-2026-55513nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5…0.2%보통5.4
CVE-2026-92920admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account, allowing attackers t…0.2%보통5.3
CVE-2026-103279Ghost versions from 3.10.0 before 6.34.0 fail to fully invalidate all sessions after a password change. Attack…0.2%높음7.6
CVE-2026-80174Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.2%보통5.3
CVE-2026-102367mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh endpoint tha…0.2%보통5.3
CVE-2026-101271OAuth credentials (access tokens) are valid for the entirety of their lifetime, even if the application (OAuth…0.2%낮음2.1
CVE-2026-66253iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattende…0.1%낮음3.1
CVE-2026-92378A session management vulnerability exists in the Legacy UI Reduced Function Login feature of NT-ware uniFLOW O…0.1%보통4.1
CVE-2026-73586Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Sessi…0.1%보통6.4
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.