Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-384 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 25 | 22 | 0 |
▂▁▁▁▁▁▁▂▁▁▁▁▁▂▁▁▁▁▁▁▄█▅▂
2025-09 0 · 2025-10 1 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 10 · 2026-07 6 · 2026-08 2
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2024-7341 | 7.1 | 55.3 | — | Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters |
| CVE-2026-41613 | 8.8 | 42.0 | — | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2025-45949 | 9.8 | 40.7 | — | — |
| CVE-2025-67446 | 9.8 | 37.9 | — | — |
| CVE-2026-12581 | 7.7 | 37.8 | — | Digiwin|EasyFlow .NET - Session Fixation |
| CVE-2026-43827 | 5.9 | 34.6 | — | Apache Shiro: Session fixation: new session is not created after login by default |
| CVE-2009-10007 | 9.1 | 30.1 | — | Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to se… |
| CVE-2026-48545 | 7.6 | 28.2 | — | Gradio < 6.15.0 Cookie Injection via Shared Proxy Client |
| CVE-2026-14609 | 2.9 | 25.0 | — | SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation |
| CVE-2021-32088 | 9.8 | 21.2 | — | — |
| CVE-2026-16496 | 8.9 | 19.7 | — | terraform-mcp-server vulnerable to cross-user credential inheritance if an MCP session … |
| CVE-2026-56425 | 9.3 | 17.7 | — | MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotatio… |
| CVE-2026-13707 | 0.0 | 15.3 | — | Session fixation attacks on improperly configured OAuth 1.0a tools |
| CVE-2026-11335 | 2.1 | 14.3 | — | tittuvarghese CollegeManagementSystem login-form.php session_start session fixiation |
| CVE-2026-40082 | 5.4 | 14.0 | — | Cacti: Session Fixation via missing session_regenerate_id() after login |
| CVE-2026-41839 | 4.2 | 9.8 | — | Spring Framework Escalation via Session Fixation in WebFlux |
| CVE-2026-56224 | 5.1 | 9.5 | — | Capgo - Login CSRF and Session Fixation via URL Query Parameters |
| CVE-2026-70594 | 6.7 | 5.7 | — | Ghost: Session Fixation in Ghost Admin |
| CVE-2026-33384 | 4.8 | 5.1 | — | Session Fixation in QuickCMS |
| CVE-2026-35095 | 4.8 | 4.3 | — | Session fixation in KTM System e-BOK |
| Vendor | CVEs |
|---|---|
| red hat | 3 |
| guzzle | 2 |
| apache | 1 |
| cacti | 1 |
| capgo | 1 |
| digiwin | 1 |
| ether | 1 |
| gradio-app | 1 |
| hashicorp | 1 |
| keycloak | 1 |
| ktm system | 1 |
| microsoft | 1 |
| misp | 1 |
| mozilla | 1 |
| opensolution | 1 |