GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,736
Maven
5,000+
npm
4,336
NuGet
764
pip
4,110
Pub
12
RubyGems
960
Rust
1,068
Swift
45
Unreviewed advisories
All unreviewed
5,000+
167 advisories
Filter by severity
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow...
Moderate
Unreviewed
CVE-2024-22351
was published
Apr 24, 2025
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0
does not invalidate session...
Moderate
Unreviewed
CVE-2024-45651
was published
Apr 18, 2025
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7...
Moderate
Unreviewed
CVE-2024-49825
was published
Apr 14, 2025
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could...
Moderate
Unreviewed
CVE-2024-25051
was published
Apr 2, 2025
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse...
Moderate
Unreviewed
CVE-2025-28132
was published
Apr 1, 2025
Incorrect cookie session handling in WombatDialer before 25.02 results in the full session...
Moderate
Unreviewed
CVE-2024-57056
was published
Feb 18, 2025
An issue discovered in GitLab CE/EE affecting all versions from 16.11 prior to 17.6.5, 17.7 prior...
Moderate
Unreviewed
CVE-2025-1198
was published
Feb 13, 2025
When multiple server blocks are configured to share the same IP address and port, an attacker can...
Moderate
Unreviewed
CVE-2025-23419
was published
Feb 5, 2025
: Insufficient Session Expiration vulnerability in Progress Sitefinity allows : Session Fixation...
Moderate
Unreviewed
CVE-2024-11627
was published
Jan 7, 2025
Missing session invalidation after user deletion. The following products are affected: Acronis...
Moderate
Unreviewed
CVE-2024-56413
was published
Jan 2, 2025
In JetBrains TeamCity before 2024.12 access tokens were not revoked after removing user roles
Moderate
Unreviewed
CVE-2024-56351
was published
Dec 20, 2024
A vulnerability was found in InvoicePlane up to 1.6.1 and classified as problematic. Affected by...
Moderate
Unreviewed
CVE-2024-12667
was published
Dec 16, 2024
An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 17.4.5, 17...
Moderate
Unreviewed
CVE-2024-11668
was published
Nov 26, 2024
IBM Watson Query on Cloud Pak for Data 1.8, 2.0, 2.1, 2.2 and IBM Db2 Big SQL on Cloud Pak for...
Moderate
Unreviewed
CVE-2024-35160
was published
Nov 23, 2024
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue...
Moderate
Unreviewed
CVE-2024-11208
was published
Nov 14, 2024
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected...
Moderate
Unreviewed
CVE-2024-46892
was published
Nov 12, 2024
Umbraco CMS logout page displayed before session expiration
Moderate
CVE-2024-48926
was published
for
Umbraco.CMS
(NuGet)
Oct 22, 2024
The logout operation in the CloudStack web interface does not expire the user session completely...
Moderate
Unreviewed
CVE-2024-45462
was published
Oct 16, 2024
IoT Haat Smart Plug IH-IN-16A-S IH-IN-16A-S v5.16.1 suffers from Insufficient Session Expiration....
Moderate
Unreviewed
CVE-2024-46040
was published
Oct 7, 2024
HCL Nomad is susceptible to an insufficient session expiration vulnerability. Under certain...
Moderate
Unreviewed
CVE-2024-23586
was published
Sep 28, 2024
IBM Aspera Shares 1.0 through 1.10.0 PL3 does not invalidate session after a password reset which...
Moderate
Unreviewed
CVE-2024-38315
was published
Sep 16, 2024
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 SP2)....
Moderate
Unreviewed
CVE-2024-32006
was published
Sep 10, 2024
Mage AI incorrectly gives privileges to users with deleted accounts
Moderate
CVE-2024-45187
was published
for
mage-ai
(pip)
Aug 23, 2024
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10...
Moderate
Unreviewed
CVE-2022-38382
was published
Aug 13, 2024
IBM Aspera Orchestrator 4.0.1 does not invalidate session after a password change which could...
Moderate
Unreviewed
CVE-2023-26288
was published
Jul 30, 2024
ProTip!
Advisories are also available from the
GraphQL API