Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-384
Weakness type CWE-384 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 53 | 49 | 1 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▄▃▂█▁
2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 10 · 2026-07 6 · 2026-08 4 · 2026-09 24 · 2026-10 1
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2026-102489 | 9.4 | 71.5 | KEV | Undisclosed RCE in Zammad v6.3 and higher |
| CVE-2024-7341 | 7.1 | 56.6 | — | Wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters |
| CVE-2026-41613 | 8.8 | 55.0 | — | Visual Studio Code Elevation of Privilege Vulnerability |
| CVE-2026-86688 | 7.4 | 53.1 | — | Session id is not renewed on authentication in ash_authentication, allowing session fix… |
| CVE-2026-82355 | 4.2 | 52.8 | — | Apache Airflow: Session cookie silently overrides explicit Authorization bearer header,… |
| CVE-2026-75171 | 9.8 | 47.4 | — | — |
| CVE-2026-77614 | 8.8 | 44.0 | — | Opencast: Session fixation in login enables account takeover via crafted link |
| CVE-2026-43827 | 5.9 | 42.9 | — | Apache Shiro: Session fixation: new session is not created after login by default |
| CVE-2025-45949 | 9.8 | 42.2 | — | — |
| CVE-2021-32088 | 9.8 | 41.9 | — | — |
| CVE-2026-95828 | 2.1 | 39.7 | — | Mstfakts College-Management-System Authentication server.php session_start session fixi… |
| CVE-2026-48545 | 7.6 | 38.5 | — | Gradio < 6.15.0 Cookie Injection via Shared Proxy Client |
| CVE-2026-64857 | 5.3 | 38.5 | — | tirreno has Session Fixation in Login Authentication |
| CVE-2026-92984 | 8.5 | 38.0 | — | HUBzero CMS through 2.2.32 Session Fixation via Query-String Session Identifier |
| CVE-2026-56425 | 9.3 | 37.9 | — | MISP AAD authentication plugin - Improper OAuth State Handling, Missing Session Rotatio… |
| CVE-2025-67446 | 9.8 | 37.2 | — | — |
| CVE-2026-12581 | 7.7 | 37.2 | — | Digiwin|EasyFlow .NET - Session Fixation |
| CVE-2026-84652 | 7.3 | 36.3 | — | — |
| CVE-2026-81826 | 9.1 | 32.5 | — | Flowintel Fails to Invalidate Active Sessions After Password Change |
| CVE-2023-50176 | 8.8 | 32.1 | — | — |