GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,875
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,159
Rust
1,590
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
20
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
263 advisories
Filter by severity
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-97212
was published
Oct 3, 2026
YesWiki before 4.6.7 contains an insufficient session expiration vulnerability that allows...
Moderate
Unreviewed
CVE-2026-104468
was published
Oct 2, 2026
mall4j through 4.0 contains an insufficient session expiration vulnerability in the token refresh...
Moderate
Unreviewed
CVE-2026-102367
was published
Sep 29, 2026
Capgo.app before 12.264.5 does not enforce upload expiry or build lifecycle state in the /build...
Moderate
Unreviewed
CVE-2026-100624
was published
Sep 26, 2026
Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login...
Moderate
Unreviewed
CVE-2026-100502
was published
Sep 26, 2026
Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an...
Moderate
Unreviewed
CVE-2026-73586
was published
Sep 23, 2026
A session management
vulnerability exists in the Legacy UI Reduced Function Login feature of NT...
Moderate
Unreviewed
CVE-2026-92378
was published
Sep 23, 2026
A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side...
Moderate
Unreviewed
CVE-2026-79317
was published
Sep 21, 2026
A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T...
Moderate
Unreviewed
CVE-2026-92976
was published
Sep 18, 2026
admin3 through 3.0.0 fails to invalidate existing sessions when disabling a user account,...
Moderate
Unreviewed
CVE-2026-92920
was published
Sep 17, 2026
A flaw was found in the first broker login flow of Keycloak. When a user confirms an account...
Moderate
Unreviewed
CVE-2026-92358
was published
Sep 16, 2026
ZITADEL: Missing Token Expiration (`exp`) Validation in JWT IdP Provider
Moderate
CVE-2026-56665
was published
for
github.com/zitadel/zitadel
(Go)
Sep 11, 2026
Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notes
Moderate
CVE-2026-87014
was published
for
open-webui
(pip)
Sep 10, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80174
was published
Sep 9, 2026
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route...
Moderate
Unreviewed
CVE-2026-82469
was published
Aug 29, 2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may...
Moderate
Unreviewed
CVE-2025-62342
was published
Aug 27, 2026
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for...
Moderate
Unreviewed
CVE-2026-73180
was published
Aug 26, 2026
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing...
Moderate
Unreviewed
CVE-2026-77130
was published
Aug 25, 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
Moderate
Unreviewed
CVE-2026-66376
was published
Aug 12, 2026
When internal roles are removed from a user within the WSO2 product, the system fails to...
Moderate
Unreviewed
CVE-2025-12317
was published
Aug 7, 2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed...
Moderate
Unreviewed
CVE-2024-8995
was published
Aug 6, 2026
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc....
Moderate
Unreviewed
CVE-2026-14465
was published
Aug 4, 2026
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable...
Moderate
Unreviewed
CVE-2026-14227
was published
Jul 30, 2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3...
Moderate
Unreviewed
CVE-2024-40683
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality...
Moderate
Unreviewed
CVE-2026-16970
was published
Jul 30, 2026
ProTip!
Advisories are also available from the
GraphQL API