Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CWE-613
Weakness type CWE-613 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
Totals
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 133 | 126 | 0 |
Monthly trend
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▅▆▅█▂
2025-11 0 · 2025-12 1 · 2026-01 0 · 2026-02 0 · 2026-03 1 · 2026-04 0 · 2026-05 5 · 2026-06 25 · 2026-07 27 · 2026-08 22 · 2026-09 41 · 2026-10 5
Top CVEs
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-0335 | 7.6 | 81.4 | — | Openstack nova: vnc proxy can connect to the wrong vm |
| CVE-2024-50562 | 4.4 | 65.8 | — | — |
| CVE-2024-13996 | 9.2 | 63.3 | — | Nagios XI < 2024R1.1.3 Session Not Invalidated After Password Change |
| CVE-2026-82310 | 7.2 | 61.7 | — | Apache Airflow FAB provider: FAB auth manager: deactivated users retain and renew Core … |
| CVE-2026-82311 | 9.8 | 60.8 | — | Apache Airflow FAB provider: FAB password reset never invalidates sessions: string/int … |
| CVE-2026-86533 | 9.1 | 58.5 | — | Revoked session accepted because the session jti is never checked in AshAuthentication … |
| CVE-2026-55250 | 8.7 | 57.4 | — | Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Ta… |
| CVE-2026-86462 | 9.1 | 56.0 | — | Apache Airflow FAB provider: FAB Admin password PATCH does not invalidate database-back… |
| CVE-2026-86473 | 9.1 | 53.3 | — | Apache Airflow: Logout ignores a presented Authorization bearer token, leaving it revoc… |
| CVE-2026-46455 | 9.8 | 51.1 | — | Apache Camel: Camel-Keycloak: The access-token validity window is not verified because … |
| CVE-2026-28564 | 9.8 | 50.8 | — | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials |
| CVE-2026-14950 | 9.2 | 49.2 | — | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Insufficient Session… |
| CVE-2026-53776 | 9.3 | 48.8 | — | Perry < 0.5.1166 JWT Expiration Bypass via verify_decode |
| CVE-2026-81637 | 2.3 | 47.2 | — | Replayable OAuth2 CSRF state retained after a failed callback in AshAuthentication |
| CVE-2026-48726 | 6.5 | 46.6 | — | Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logo… |
| CVE-2022-50692 | 6.9 | 46.1 | — | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability |
| CVE-2026-88262 | 8.7 | 45.6 | — | — |
| CVE-2026-12796 | 2.1 | 45.2 | — | BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid ses… |
| CVE-2026-48329 | 2.7 | 45.1 | — | ColdFusion | Insufficient Session Expiration (CWE-613) |
| CVE-2026-60053 | 9.1 | 45.0 | — | Apache Answer: Residual Administrative API Key Access After Role or Account Revocation |
Most-affected vendors
| Vendor | CVEs |
|---|---|
| apache | 9 |
| openclaw | 5 |
| red hat | 5 |
| ibm | 4 |
| hcl software | 3 |
| nocodb | 3 |
| open-webui | 3 |
| team-alembic | 3 |
| wso2 | 3 |
| berriai | 2 |
| bludit | 2 |
| dell | 2 |
| fortinet | 2 |
| getgrav | 2 |
| hexpm | 2 |