GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
150 advisories
Filter by severity
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack...
High
Unreviewed
CVE-2026-104469
was published
Oct 2, 2026
The application accepts user-supplied session identifiers and does not regenerate the session ID...
High
Unreviewed
CVE-2026-71302
was published
Sep 30, 2026
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
High
CVE-2026-61687
was published
for
hatchet
(Go)
Sep 21, 2026
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables...
High
Unreviewed
CVE-2026-92984
was published
Sep 17, 2026
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
High
CVE-2026-61592
was published
for
djust
(pip)
Sep 16, 2026
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation....
High
Unreviewed
CVE-2026-1758
was published
Sep 15, 2026
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege...
High
Unreviewed
CVE-2026-76196
was published
Sep 8, 2026
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom...
High
Unreviewed
CVE-2026-85238
was published
Sep 3, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a...
High
Unreviewed
CVE-2026-84652
was published
Sep 2, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the...
High
Unreviewed
CVE-2026-16496
was published
Jul 28, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated...
High
Unreviewed
CVE-2026-12581
was published
Jun 22, 2026
Gradio contains a cookie injection vulnerability
High
CVE-2026-48545
was published
for
gradio
(pip)
May 27, 2026
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue...
High
Unreviewed
CVE-2026-30808
was published
May 12, 2026
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
High
CVE-2026-44553
was published
for
open-webui
(pip)
May 8, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
High
CVE-2026-33492
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Rancher's Azure AD permission changes are not reflected on active sessions
High
CVE-2023-22648
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy...
High
Unreviewed
CVE-2026-22082
was published
Jan 9, 2026
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows...
High
Unreviewed
CVE-2020-36913
was published
Jan 6, 2026
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53775
was published
Dec 11, 2025
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53776
was published
Dec 11, 2025
Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53741
was published
Dec 10, 2025
Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session...
High
Unreviewed
CVE-2025-10228
was published
Oct 14, 2025
ProTip!
Advisories are also available from the
GraphQL API