CWE-488
23 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-488page 1 of 1
- CVE-2022-40210MEDIUMCVSS 6.8EG 6.82023-05-10
Exposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2023-1907HIGHCVSS 8.0EG 8.02025-01-09
A vulnerability was found in pgadmin. Users logging into pgAdmin running in server mode using LDAP authentication may be attached to another user's session if multiple connection attempts occur simultaneously.
- CVE-2023-6519HIGHCVSS 7.5EG 7.52024-02-08
Exposure of Data Element to Wrong Session vulnerability in Mia Technology Inc. MİA-MED allows Read Sensitive Strings Within an Executable. This issue affects MİA-MED: before 1.0.7.
- CVE-2024-11094MEDIUMCVSS 5.3EG 5.32024-11-16
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract data such as redire…
- CVE-2024-1223MEDIUMCVSS 4.8EG 4.82024-03-14
This vulnerability potentially allows unauthorized enumeration of information from the embedded device APIs. An attacker must already have existing knowledge of some combination of valid usernames, device names and an internal system key. …
- CVE-2024-27455CRITICALCVSS 9.1EG 9.12024-02-26
In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Assetwise ALIM Web 23.00.04.04 and Assetwise Information Integ…
- CVE-2024-27935HIGHCVSS 7.2EG 7.22024-03-21
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.35.1 and prior to version 1.36.3, a vulnerability in Deno's Node.js compatibility runtime allows for cross-session data contamination during simultaneous asyn…
- CVE-2024-38367HIGHCVSS 8.2EG 8.22024-07-01
trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification step could be manipulated for owner session hijacking Comprom…
- CVE-2024-41977HIGHCVSS 7.1EG 7.12024-08-13
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.1), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8…
- CVE-2024-5148HIGHCVSS 7.5EG 7.52024-09-02
A flaw was found in the gnome-remote-desktop package. The gnome-remote-desktop system daemon performs inadequate validation of session agents using D-Bus methods related to transitioning a client connection from the login screen to the use…
- CVE-2024-6162HIGHCVSS 7.5EG 7.52024-06-20
A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneo…
- CVE-2024-7049MEDIUMCVSS 5.4EG 5.42024-10-10
In version v0.3.8 of open-webui/open-webui, a vulnerability exists where a token is returned when a user with a pending role logs in. This allows the user to perform actions without admin confirmation, bypassing the intended approval proce…
- CVE-2024-8314MEDIUMCVSS 5.5EG 0.02025-03-25
An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently a…
- CVE-2025-1247HIGHCVSS 8.3EG 8.32025-02-13
A flaw was found in Quarkus REST that allows request parameters to leak between concurrent requests if endpoints use field injection without a CDI scope. This vulnerability allows attackers to manipulate request data, impersonate users, or…
- CVE-2025-2312MEDIUMCVSS 5.9EG 5.92025-03-25
A flaw was found in cifs-utils. When trying to obtain Kerberos credentials, the cifs.upcall program from the cifs-utils package makes an upcall to the wrong namespace in containerized environments. This issue may lead to disclosing sensiti…
- CVE-2025-24934MEDIUMCVSS 5.4EG 5.42025-10-22
Software which sets SO_REUSEPORT_LB on a socket and then connects it to a host will not directly observe any problems. However, due to its membership in a load-balancing group, that socket will receive packets originating from any host. …
- CVE-2025-27606MEDIUMCVSS 5.1EG 5.12025-03-14
Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attack…
- CVE-2025-30073HIGHCVSS 7.5EG 7.52025-03-26
An issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a payment, the first or all transactions with the same reference are completed, depending on timing. …
- CVE-2025-47928CRITICALCVSS 9.1EG 9.12025-05-15
Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` followed by the checking out the head.sha of a forked PR c…
- CVE-2026-23646MEDIUMCVSS 6.5EG 6.52026-01-19
OpenProject is an open-source, web-based project management software. Users of OpenProject versions prior to 16.6.5 and 17.0.1 have the ability to view and end their active sessions via Account Settings → Sessions. When deleting a sessio…
- CVE-2026-23844MEDIUMCVSS 4.3EG 4.32026-01-19
Whisper Money is a personal finance application. Versions prior to 0.1.5 have an insecure direct object reference vulnerability. A user can update/create account balances in other users' bank accounts. Version 0.1.5 fixes the issue.
- CVE-2026-46416MEDIUMCVSS 6.3EG 6.32026-05-27
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for multiple authenticated WebSocket connections…
- CVE-2026-9831MEDIUMCVSS 6.3EG 6.32026-05-29
A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with an Extreme Platform ONE /IAM-issued API…
Map vulnerabilities like CWE-488 to your infrastructure
EchelonGraph correlates every CVE — across CWE-488 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →