GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
26 advisories
Filter by severity
A vulnerability has been found in kishor-23 food-waste-management-system...
Low
Unreviewed
CVE-2026-105233
was published
Oct 5, 2026
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in...
Low
Unreviewed
CVE-2026-101268
was published
Sep 29, 2026
A vulnerability was determined in Mstfakts College-Management-System. This affects the function...
Low
Unreviewed
CVE-2026-95828
was published
Sep 23, 2026
A vulnerability was found in ningzichun Student Management System up to...
Low
Unreviewed
CVE-2026-86674
was published
Sep 8, 2026
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management &...
Low
Unreviewed
CVE-2026-86279
was published
Sep 7, 2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive...
Low
Unreviewed
CVE-2026-14609
was published
Jul 3, 2026
Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated...
Low
Unreviewed
CVE-2026-13707
was published
Jul 1, 2026
A flaw has been found in tittuvarghese CollegeManagementSystem...
Low
Unreviewed
CVE-2026-11335
was published
Jun 5, 2026
OAuth2 Proxy's session cookies are not cleared when rendering sign-in page
Low
CVE-2026-34454
was published
for
github.com/oauth2-proxy/oauth2-proxy/v7
(Go)
Apr 14, 2026
A session management issue was addressed with improved checks. This issue is fixed in macOS...
Low
Unreviewed
CVE-2025-43516
was published
Dec 12, 2025
Overhang Tutor Discloses Sensitive Information due to Improper Cache-Control
Low
CVE-2025-65681
was published
for
tutor
(pip)
Nov 26, 2025
Creativeitem Academy LMS up to and including 5.13 does not regenerate session IDs upon successful...
Low
Unreviewed
CVE-2025-56746
was published
Oct 15, 2025
HCL IEM is affected by a cookie attribute not set vulnerability due to inconsistency of certain...
Low
Unreviewed
CVE-2025-0253
was published
Jul 25, 2025
HCL IEM is affected by a concurrent login vulnerability. The application allows multiple...
Low
Unreviewed
CVE-2025-0251
was published
Jul 25, 2025
Internet Starter, one of SoftCOM iKSORIS system modules, allows for setting an arbitrary session...
Low
Unreviewed
CVE-2024-49709
was published
Apr 14, 2025
Mattermost fails to invalidate all active sessions when converting a user to a bot
Low
CVE-2025-1412
was published
for
github.com/mattermost/mattermost/server/v8
(Go)
Feb 24, 2025
Enabling Authentication does not close all logged in socket connections immediately
Low
GHSA-23q2-5gf8-gjpp
was published
for
uptime-kuma
(npm)
Apr 19, 2024
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive...
Low
Unreviewed
CVE-2023-45718
was published
Feb 10, 2024
A vulnerability classified as problematic has been found in SourceCodester Engineers Online...
Low
Unreviewed
CVE-2024-0351
was published
Jan 10, 2024
Initially, a user opens a Private Browsing Window and generates a password for a site, then...
Low
Unreviewed
CVE-2020-6824
was published
May 24, 2022
IBM Security Identity Manager Virtual Appliance does not invalidate session tokens which could...
Low
Unreviewed
CVE-2016-9703
was published
May 17, 2022
IBM Security Guardium 10.0 does not renew a session variable after a successful authentication...
Low
Unreviewed
CVE-2017-1270
was published
May 14, 2022
Symfony Session Fixation Vulnerability
Low
CVE-2015-8124
was published
for
symfony/security
(Composer)
May 14, 2022
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could...
Low
Unreviewed
CVE-2018-16463
was published
May 13, 2022
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the...
Low
Unreviewed
CVE-2018-1962
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API