GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
387 advisories
Filter by severity
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom...
High
Unreviewed
CVE-2026-85238
was published
Sep 3, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a...
High
Unreviewed
CVE-2026-84652
was published
Sep 2, 2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could...
Critical
Unreviewed
CVE-2026-18527
was published
Aug 29, 2026
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s...
Critical
Unreviewed
CVE-2026-81826
was published
Aug 27, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the...
High
Unreviewed
CVE-2026-16496
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API...
Critical
Unreviewed
CVE-2021-32088
was published
Jul 28, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue...
Moderate
Unreviewed
CVE-2026-16089
was published
Jul 17, 2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive...
Low
Unreviewed
CVE-2026-14609
was published
Jul 3, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
Session fixation vulnerability in Wikimedia Foundation OAuth.
This vulnerability is associated...
Low
Unreviewed
CVE-2026-13707
was published
Jul 1, 2026
Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query...
Moderate
Unreviewed
CVE-2026-56224
was published
Jul 1, 2026
KTM System e-BOK allows the session identifier to be set by the client prior to authentication....
Moderate
Unreviewed
CVE-2026-35095
was published
Jun 30, 2026
The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in...
Critical
Unreviewed
CVE-2026-56425
was published
Jun 22, 2026
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated...
High
Unreviewed
CVE-2026-12581
was published
Jun 22, 2026
Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session...
Critical
Unreviewed
CVE-2009-10007
was published
Jun 9, 2026
Spring Framework Escalation via Session Fixation in WebFlux
Moderate
CVE-2026-41839
was published
for
org.springframework:spring-webflux
(Maven)
Jun 9, 2026
A flaw has been found in tittuvarghese CollegeManagementSystem...
Low
Unreviewed
CVE-2026-11335
was published
Jun 5, 2026
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03...
Critical
Unreviewed
CVE-2025-67446
was published
Jun 4, 2026
QuickCMS allows a user's session identifier to be set before authentication. The value of this...
Moderate
Unreviewed
CVE-2026-33384
was published
May 29, 2026
Gradio contains a cookie injection vulnerability
High
CVE-2026-48545
was published
for
gradio
(pip)
May 27, 2026
Apache Shiro has a session fixation vulnerability
Moderate
CVE-2026-43827
was published
for
org.apache.shiro:shiro-core
(Maven)
May 26, 2026
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue...
High
Unreviewed
CVE-2026-30808
was published
May 12, 2026
ProTip!
Advisories are also available from the
GraphQL API