GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
406 advisories
Filter by severity
A vulnerability has been found in kishor-23 food-waste-management-system...
Low
Unreviewed
CVE-2026-105233
was published
Oct 5, 2026
Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote...
Critical
Unreviewed
CVE-2026-102489
was published
Sep 30, 2026
YesWiki before 4.6.7 contains a session fixation vulnerability that allows attackers to hijack...
High
Unreviewed
CVE-2026-104469
was published
Oct 2, 2026
The application accepts user-supplied session identifiers and does not regenerate the session ID...
High
Unreviewed
CVE-2026-71302
was published
Sep 30, 2026
If an attacker is able to convince a victim on a specially crafted link, the victim is logged in...
Low
Unreviewed
CVE-2026-101268
was published
Sep 29, 2026
Session fixation in HTTP management authentication allows remote attackers to gain unauthorized...
Critical
Unreviewed
CVE-2026-92609
was published
Sep 25, 2026
social-auth-core has a Session Fixation issue
Moderate
CVE-2026-57179
was published
for
social-auth-core
(pip)
Sep 24, 2026
A vulnerability was determined in Mstfakts College-Management-System. This affects the function...
Low
Unreviewed
CVE-2026-95828
was published
Sep 23, 2026
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads...
Moderate
Unreviewed
CVE-2026-79312
was published
Sep 22, 2026
When a request to the Airflow core API carries both a session cookie and an explicit ...
Moderate
Unreviewed
CVE-2026-82355
was published
Sep 21, 2026
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
High
CVE-2026-61687
was published
for
hatchet
(Go)
Sep 21, 2026
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables...
High
Unreviewed
CVE-2026-92984
was published
Sep 17, 2026
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
High
CVE-2026-61592
was published
for
djust
(pip)
Sep 16, 2026
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue...
Moderate
Unreviewed
CVE-2026-16089
was published
Jul 17, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation....
High
Unreviewed
CVE-2026-1758
was published
Sep 15, 2026
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID...
Critical
Unreviewed
CVE-2026-75171
was published
Sep 4, 2026
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom...
High
Unreviewed
CVE-2026-85238
was published
Sep 3, 2026
A vulnerability was found in ningzichun Student Management System up to...
Low
Unreviewed
CVE-2026-86674
was published
Sep 8, 2026
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege...
High
Unreviewed
CVE-2026-76196
was published
Sep 8, 2026
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management &...
Low
Unreviewed
CVE-2026-86279
was published
Sep 7, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a...
High
Unreviewed
CVE-2026-84652
was published
Sep 2, 2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could...
Critical
Unreviewed
CVE-2026-18527
was published
Aug 29, 2026
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s...
Critical
Unreviewed
CVE-2026-81826
was published
Aug 27, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
ProTip!
Advisories are also available from the
GraphQL API