GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,521
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
383 advisories
Filter by severity
IBM Security Guardium Big Data Intelligence (SonarG) 3.1 does not renew a session variable after...
High
Unreviewed
CVE-2018-1375
was published
May 13, 2022
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the 'HttpOnly'...
Moderate
Unreviewed
CVE-2018-1480
was published
May 13, 2022
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable...
Moderate
Unreviewed
CVE-2018-1485
was published
May 13, 2022
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute...
Moderate
Unreviewed
CVE-2018-1484
was published
May 13, 2022
IBM Jazz Foundation products could allow a user with physical access to the system to log in as...
Moderate
Unreviewed
CVE-2018-1492
was published
May 13, 2022
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session...
Moderate
Unreviewed
CVE-2018-1626
was published
May 13, 2022
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not...
Moderate
Unreviewed
CVE-2018-1804
was published
May 13, 2022
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not...
Moderate
Unreviewed
CVE-2018-1948
was published
May 13, 2022
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the...
Low
Unreviewed
CVE-2018-1962
was published
May 13, 2022
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI...
High
Unreviewed
CVE-2018-2408
was published
May 13, 2022
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud...
High
Unreviewed
CVE-2018-2409
was published
May 13, 2022
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a...
High
Unreviewed
CVE-2018-5385
was published
May 13, 2022
A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000,...
High
Unreviewed
CVE-2018-5465
was published
May 13, 2022
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or...
High
Unreviewed
CVE-2018-8852
was published
May 13, 2022
GitHub Authentication Plugin session fixation vulnerability
Moderate
CVE-2019-1003019
was published
for
org.jenkins-ci.plugins:github-oauth
(Maven)
May 13, 2022
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed....
Moderate
Unreviewed
CVE-2019-3784
was published
May 13, 2022
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens...
High
Unreviewed
CVE-2019-11213
was published
May 13, 2022
Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before...
High
Unreviewed
CVE-2019-0102
was published
May 13, 2022
Moodle Session Fixation vulnerability
Moderate
CVE-2010-1613
was published
for
moodle/moodle
(Composer)
May 13, 2022
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to...
High
Unreviewed
CVE-2018-9026
was published
May 13, 2022
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time...
High
Unreviewed
CVE-2018-17199
was published
May 13, 2022
Session Fixation in Apache CXF
High
CVE-2017-5656
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1...
High
Unreviewed
CVE-2018-6434
was published
May 13, 2022
Authentication library in TYPO3 vulnerable to session fixation
High
CVE-2009-0256
was published
for
typo3/cms
(Composer)
May 2, 2022
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed...
Moderate
Unreviewed
CVE-2008-3222
was published
May 1, 2022
ProTip!
Advisories are also available from the
GraphQL API