GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,750
Erlang
35
GitHub Actions
29
Go
2,323
Maven
5,000+
npm
3,956
NuGet
712
pip
3,739
Pub
12
RubyGems
921
Rust
973
Swift
38
Unreviewed advisories
All unreviewed
5,000+
126 advisories
Filter by severity
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access...
Moderate
Unreviewed
CVE-2025-26658
was published
Mar 11, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
with Watson Assistant chat feature...
Moderate
Unreviewed
CVE-2024-49344
was published
Feb 20, 2025
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim...
Moderate
Unreviewed
CVE-2024-42207
was published
Feb 5, 2025
A UAA configured with multiple identity zones, does not properly validate session information...
Moderate
Unreviewed
CVE-2025-22216
was published
Jan 31, 2025
An improper session validation allows an unauthenticated attacker to cause certain request...
Moderate
Unreviewed
CVE-2025-24502
was published
Jan 30, 2025
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this...
Moderate
Unreviewed
CVE-2024-42170
was published
Jan 11, 2025
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this...
Moderate
Unreviewed
CVE-2024-42171
was published
Jan 11, 2025
Password Pusher Allows Session Token Interception Leading to Potential Hijacking
Moderate
CVE-2024-56733
was published
for
pwpush
(RubyGems)
Dec 30, 2024
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the...
Moderate
Unreviewed
CVE-2024-28144
was published
Dec 12, 2024
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The...
Moderate
Unreviewed
CVE-2021-3740
was published
Nov 15, 2024
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation,...
Moderate
Unreviewed
CVE-2024-10318
was published
Nov 6, 2024
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Moderate
CVE-2024-48929
was published
for
Umbraco.CMS
(NuGet)
Oct 22, 2024
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0....
Moderate
Unreviewed
CVE-2024-10158
was published
Oct 20, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2)....
Moderate
Unreviewed
CVE-2024-42345
was published
Sep 10, 2024
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could...
Moderate
Unreviewed
CVE-2023-38018
was published
Aug 12, 2024
Zend-Session session validation vulnerability
Moderate
GHSA-96c6-m98x-hxjx
was published
for
zendframework/zend-session
(Composer)
Jun 7, 2024
Zendframework session validation vulnerability
Moderate
GHSA-62f6-h68r-3jpw
was published
for
zendframework/zendframework
(Composer)
Jun 7, 2024
Unauthenticated Access to sensitive settings in Argo CD
Moderate
CVE-2024-37152
was published
for
github.com/argoproj/argo-cd/v2/server
(Go)
Jun 6, 2024
TYPO3 Security Misconfiguration in User Session Handling
Moderate
GHSA-xmgr-jff3-fcfv
was published
for
typo3/cms-core
(Composer)
May 30, 2024
Laravel Hijacked authentication cookies vulnerability
Moderate
GHSA-p62r-7637-3wwc
was published
for
laravel/framework
(Composer)
May 15, 2024
Laravel Hijacked authentication cookies vulnerability
Moderate
GHSA-q4xf-7fw5-4x8v
was published
for
illuminate/auth
(Composer)
May 15, 2024
E-Mails exported as PDF were stored in a cache that did not consider specific session information...
Moderate
Unreviewed
CVE-2024-23193
was published
May 6, 2024
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or...
Moderate
Unreviewed
CVE-2023-38002
was published
Apr 30, 2024
Keycloak vulnerable to session hijacking via re-authentication
Moderate
CVE-2023-6787
was published
for
org.keycloak:keycloak-services
(Maven)
Apr 17, 2024
zenml Session Fixation vulnerability
Moderate
CVE-2024-2260
was published
for
zenml
(pip)
Apr 16, 2024
ProTip!
Advisories are also available from the
GraphQL API