GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,517
Rust
20
72 advisories
Filter by severity
webpy web.py 0.76 is vulnerable to Insufficient Session Expiration. The application's session...
Critical
Unreviewed
CVE-2026-79313
was published
Sep 22, 2026
Apache Airflow: the Core API logout endpoint revokes only a session token presented as the _token...
Critical
Unreviewed
CVE-2026-86473
was published
Sep 21, 2026
Apache Airflow FAB provider: resetting a user's password does not delete that user's existing...
Critical
Unreviewed
CVE-2026-82311
was published
Sep 16, 2026
Apache Airflow FAB provider: changing a user's password through the Admin user-edit PATCH...
Critical
Unreviewed
CVE-2026-86462
was published
Sep 16, 2026
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php,...
Critical
Unreviewed
CVE-2026-84480
was published
Sep 2, 2026
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option,...
Critical
Unreviewed
CVE-2026-79664
was published
Aug 25, 2026
An unauthenticated remote attacker in possession of a valid session identifier is able to...
Critical
Unreviewed
CVE-2026-14950
was published
Aug 20, 2026
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer...
Critical
Unreviewed
CVE-2026-60053
was published
Aug 5, 2026
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers...
Critical
Unreviewed
CVE-2026-64829
was published
Jul 22, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing...
Critical
Unreviewed
CVE-2026-56400
was published
Jul 15, 2026
Apache Camel-Keycloak: The access-token validity window is not verified because the IS_ACTIVE check is missing from the TokenVerifier, allowing expired tokens to be accepted
Critical
CVE-2026-46455
was published
for
org.apache.camel:camel-keycloak
(Maven)
Jul 6, 2026
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows...
Critical
Unreviewed
CVE-2026-8670
was published
May 26, 2026
Apache Airflow: JWT token still valid after logout
Critical
CVE-2025-57735
was published
for
apache-airflow
(pip)
Apr 9, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
Critical
CVE-2026-27575
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to...
Critical
Unreviewed
CVE-2026-1435
was published
Feb 18, 2026
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user...
Critical
Unreviewed
CVE-2025-56643
was published
Nov 18, 2025
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user...
Critical
Unreviewed
CVE-2024-13996
was published
Oct 31, 2025
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user...
Critical
Unreviewed
CVE-2025-24859
was published
Apr 14, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS...
Critical
Unreviewed
CVE-2025-24106
was published
Jan 28, 2025
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing...
Critical
Unreviewed
CVE-2024-13280
was published
Jan 9, 2025
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in...
Critical
Unreviewed
CVE-2021-35473
was published
Nov 11, 2024
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1...
Critical
Unreviewed
CVE-2024-8888
was published
Sep 18, 2024
On versions before 2.1.4, session is not invalidated after logout. When the user logged in...
Critical
Unreviewed
CVE-2024-29070
was published
Jul 23, 2024
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an...
Critical
Unreviewed
CVE-2024-35049
was published
May 14, 2024
ProTip!
Advisories are also available from the
GraphQL API