The product does not sufficiently enforce boundaries between the states of different sessions, causing data to be provided to, or used by, the wrong session.
Volume of CVEs assigned to CWE-488 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-38367CRITICAL trunk.cocoapods.org is the authentication server for the CoacoaPods dependency manager. Prior to commit d4fa66f49cedab449af9a56a21ab40697b9f7b97, the trunk sessions verification st | Jul 1, 2024 | 9.6 | 33 | NO | NO |
CVE-2026-54497MEDIUM view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4.0.0 until 4.12.0, ViewComponent::Base instances retain rend | Jul 17, 2026 | 6.8 | 30 | NO | NO |
CVE-2026-54311HIGH n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows could pollute the sandbox used b | Jun 23, 2026 | 7.7 | 30 | NO | NO |
CVE-2026-9831MEDIUM A race condition in the shared Extreme Platform
ONE IAM Gateway API-key authentication path could, under specific
high-concurrency traffic conditions, intermittently allow requests | May 29, 2026 | 6.3 | 29 | NO | NO |
CVE-2025-15576HIGH If two sibling jails are restricted to separate filesystem trees, which is to say that neither of the two jail root directories is an ancestor of the other, jailed processes may no | Mar 9, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-46416MEDIUM Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and | May 27, 2026 | 6.3 | 25 | NO | NO |
CVE-2024-27455CRITICAL In the Bentley ALIM Web application, certain configuration settings can cause exposure of a user's ALIM session token when the user attempts to download files. This is fixed in Ass | Feb 26, 2024 | 9.1 | 25 | NO | NO |
CVE-2026-34391HIGH Fleet is open source device management software. Prior to 4.81.1, a vulnerability in Fleet's Windows MDM command processing allows a malicious enrolled device to access MDM command | Mar 27, 2026 | 7.5 | 24 | NO | NO |
CVE-2026-23919HIGH For performance reasons Zabbix Server/Proxy reuses JavaScript (Duktape) contexts (used in script items, JavaScript reprocessing, Webhooks). This can lead to confidentiality loss wh | Mar 24, 2026 | 7.1 | 24 | NO | NO |
CVE-2025-47928CRITICAL Spotipy is a Python library for the Spotify Web API. As of commit 4f5759dbfb4506c7b6280572a4db1aabc1ac778d, using `pull_request_target` on `.github/workflows/integration_tests.yml` | May 15, 2025 | 9.1 | 24 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.