Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Weakness type CWE-613 — authoritative definition at MITRE. A cumulative reference aggregating every published CVE mapped to this weakness class; not a page of record.
| CVEs all-time | CVEs YTD | KEV all-time |
|---|---|---|
| 73 | 69 | 0 |
▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▁▁▁▁▁▁▁▁▁▂▇█▄
2025-09 0 · 2025-10 0 · 2025-11 0 · 2025-12 0 · 2026-01 0 · 2026-02 0 · 2026-03 0 · 2026-04 0 · 2026-05 4 · 2026-06 25 · 2026-07 27 · 2026-08 13
| CVE | CVSS | EPSS %ile | KEV | Title |
|---|---|---|---|---|
| CVE-2013-0335 | 7.6 | 80.4 | — | Openstack nova: vnc proxy can connect to the wrong vm |
| CVE-2024-50562 | 4.4 | 62.4 | — | — |
| CVE-2026-65984 | 7.5 | 38.7 | — | FUXA: JWT lifecycle flaws allow deleted or demoted users to retain privileged sessions |
| CVE-2026-44383 | 8.7 | 37.4 | — | Hydro-Québec Le Circuit Electrique charging station backend Insufficient Session Expira… |
| CVE-2026-28564 | 9.8 | 36.9 | — | Apache IoTDB: REST Basic Authentication Accepts Stale Cached Credentials |
| CVE-2026-46455 | 9.8 | 35.7 | — | Apache Camel: Camel-Keycloak: The access-token validity window is not verified because … |
| CVE-2025-4754 | 2.3 | 35.0 | — | Missing Session Revocation on Logout in ash_authentication_phoenix |
| CVE-2025-4528 | 2.1 | 33.0 | — | Dígitro NGC Explorer session expiration |
| CVE-2026-44648 | 7.5 | 32.8 | — | SillyTavern: Existing sessions are not invalidated after password change, allowing sess… |
| CVE-2026-48079 | 7.4 | 31.9 | — | OpenReception's logout page clears local access_token before server-side revocation, le… |
| CVE-2026-48726 | 6.5 | 31.5 | — | Apache Airflow: revoke_token() unreachable in FabAuthManager / KeycloakAuthManager logo… |
| CVE-2026-12796 | 2.1 | 29.1 | — | BerriAI litellm SSO Authentication Flow ui_sso.py get_redirect_response_from_openid ses… |
| CVE-2026-53776 | 9.3 | 29.0 | — | Perry < 0.5.1166 JWT Expiration Bypass via verify_decode |
| CVE-2026-60053 | 9.1 | 28.0 | — | Apache Answer: Residual Administrative API Key Access After Role or Account Revocation |
| CVE-2026-56400 | 9.0 | 28.0 | — | open-webui - Remote Code Execution via CORS Misconfiguration and Session Validation |
| CVE-2026-9162 | 4.3 | 26.5 | — | Global session revocation does not invalidate active WebSocket connections |
| CVE-2026-64829 | 9.1 | 25.1 | — | Question2Answer 1.8.8 Session Fixation via Forgot-Password Flow |
| CVE-2026-45791 | 5.9 | 25.1 | — | Dokploy: Password Change Does Not Revoke Active Sessions |
| CVE-2025-71335 | 8.6 | 24.9 | — | Flowise - Session Invalidation Failure After Password Change |
| CVE-2026-46401 | 5.3 | 23.9 | — | HAX CMS PHP has Insufficient Session Expiration |
| Vendor | CVEs |
|---|---|
| apache | 4 |
| red hat | 4 |
| ibm | 3 |
| nocodb | 3 |
| openclaw | 3 |
| wso2 | 3 |
| berriai | 2 |
| bludit | 2 |
| getgrav | 2 |
| open-webui | 2 |
| rocketchat | 2 |
| zitadel | 2 |
| actualbudget | 1 |
| adobe | 1 |
| ash-project | 1 |