Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-384'

View all threats tagged with 'cwe-384'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-384

Threats Tagged 'cwe-384'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-41839: CWE-384: Session Fixation in Spring Spring FrameworkCVE-2026-41839
0

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

Join the discussion
CVE-2024-8643: CWE-384 Session Fixation in Oceanic Software ValeAppCVE-2024-8643
0

Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0.

Join the discussion
CVE-2026-33384: CWE-384 Session Fixation in OpenSolution QuickCMSCVE-2026-33384
0

QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable.

Join the discussion
CVE-2026-43827: CWE-384 Session Fixation in Apache Software Foundation Apache ShiroCVE-2026-43827
0

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1, or 3.0.0-alpha-2 or later, which fixes the issue. In the affected versions, when a session already exists, it is not invalidated upon successful login, nor is a new session being generated with a new ID.

Join the discussion
CVE-2026-45773: CWE-352: Cross-Site Request Forgery (CSRF) in vercel turborepoCVE-2026-45773
0

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the localhost callback. While the CLI was waiting for authentication, a malicious web page could send a request to the local callback server with an attacker-controlled token. If accepted before the legitimate callback, the CLI could complete login with the wrong credentials. This affects users authenticating the turbo CLI against self-hosted remote cache/auth endpoints. Vercel-hosted login flows using device authorization are not affected. This vulnerability is fixed in 2.9.14.

Join the discussion
CVE-2026-41613: CWE-384: Session Fixation in Microsoft Visual Studio CodeCVE-2026-41613
0

Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.

Join the discussion
CVE-2025-46605: CWE-384: Session Fixation in Dell PowerProtect Data DomainCVE-2025-46605
0

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain a session fixation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access.

Join the discussion
CVE-2026-31940: CWE-384: Session Fixation in chamilo chamilo-lmsCVE-2026-31940
0

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, in main/lp/aicc_hacp.php, user-controlled request parameters are directly used to set the PHP session ID before loading global bootstrap. This leads to session fixation. This vulnerability is fixed in 1.11.38 and 2.0.0-RC.3.

Join the discussion
CVE-2026-33946: CWE-384: Session Fixation in modelcontextprotocol ruby-sdkCVE-2026-33946
0

MCP Ruby SDK is the official Ruby SDK for Model Context Protocol servers and clients. Prior to version 0.9.2, the Ruby SDK's streamable_http_transport.rb implementation contains a session hijacking vulnerability. An attacker who obtains a valid session ID can completely hijack the victim's Server-Sent Events (SSE) stream and intercept all real-time data. Version 0.9.2 contains a patch.

Join the discussion
CVE-2025-55266: CWE-384: Session Fixation in HCL Aftermarket DPCCVE-2025-55266
0

HCL Aftermarket DPC is affected by Session Fixation which allows attacker to takeover the user's session and use it carry out unauthorized transaction behalf of the user.

Join the discussion

Showing 1 to 10 of 35 results

Filters:Tag: cwe-384
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses