Threats Tagged 'cwe-384'
View all threats tagged with 'cwe-384'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-384'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-12581: CWE-384 Session fixation in Digiwin EasyFlow .NETCVE-2026-12581 0 EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user logs in. Join the discussion | CVE Database V5 | 06/22/2026, 09:30:38 UTC Added: 06/22/2026, 10:09:22 UTC |
CVE-2026-41839: CWE-384: Session Fixation in Spring Spring FrameworkCVE-2026-41839 0 A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. Join the discussion | CVE Database V5 | 06/09/2026, 03:49:52 UTC Added: 06/09/2026, 04:48:46 UTC |
CVE-2024-8643: CWE-384 Session Fixation in Oceanic Software ValeAppCVE-2024-8643 0 Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking. This issue affects ValeApp: before v2.0.0. Join the discussion | CVE Database V5 | 09/27/2024, 11:53:44 UTC Added: 06/02/2026, 08:33:44 UTC |
CVE-2026-33384: CWE-384 Session Fixation in OpenSolution QuickCMSCVE-2026-33384 0 QuickCMS allows a user's session identifier to be set before authentication. The value of this session ID stays the same after authentication. This behaviour enables an attacker to fix a session ID for a victim and later hijack the authenticated session. This issue was fixed in a patch to version 6.8 published on 15.05.2026, deployments without this patch are still vulnerable. Join the discussion | CVE Database V5 | 05/29/2026, 15:12:14 UTC Added: 05/29/2026, 16:18:43 UTC |
Showing 1 to 4 of 4 results