The product uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
Volume of CVEs assigned to CWE-324 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-35401HIGH An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to ful | Jan 10, 2023 | 8.1 | 37 | NO | NO |
CVE-2025-2291CRITICAL Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, which allows an attacker to log in with an already expired p | Apr 16, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-36031CRITICAL In the Linux kernel, the following vulnerability has been resolved:
keys: Fix overwrite of key expiration on instantiation
The expiry time of a key is unconditionally overwritten | May 30, 2024 | 9.8 | 29 | NO | NO |
CVE-2026-52809MEDIUM Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.A | Jun 24, 2026 | 6.8 | 28 | NO | NO |
CVE-2025-33012HIGH IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux could allow an authenticated user to regain access after account | Nov 7, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-24732HIGH Maddy Mail Server is an open source SMTP compatible email server. Versions of maddy prior to 0.5.4 do not implement password expiry or account expiry checking when authenticating u | Mar 9, 2022 | 8.8 | 27 | NO | NO |
CVE-2025-31123HIGH Zitadel is open-source identity infrastructure software. A vulnerability existed where expired keys can be used to retrieve tokens. Specifically, ZITADEL fails to properly check th | Mar 31, 2025 | 8.7 | 25 | NO | NO |
CVE-2025-13723HIGH IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to obtain sensitive user information using an expired access tok | Mar 13, 2026 | 7.5 | 24 | NO | NO |
CVE-2021-33020HIGH Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing windo | Apr 1, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-31895MEDIUM IBM App Connect Enterprise 12.0.1.0 through 12.0.12.1 could allow an authenticated user to obtain sensitive user information using an expired access token. IBM X-Force ID: 288176 | May 22, 2024 | 6.5 | 19 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.