GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
143 advisories
Filter by severity
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom...
High
Unreviewed
CVE-2026-85238
was published
Sep 3, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a...
High
Unreviewed
CVE-2026-84652
was published
Sep 2, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the...
High
Unreviewed
CVE-2026-16496
was published
Jul 28, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated...
High
Unreviewed
CVE-2026-12581
was published
Jun 22, 2026
Gradio contains a cookie injection vulnerability
High
CVE-2026-48545
was published
for
gradio
(pip)
May 27, 2026
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue...
High
Unreviewed
CVE-2026-30808
was published
May 12, 2026
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
High
CVE-2026-44553
was published
for
open-webui
(pip)
May 8, 2026
MCP Ruby SDK: Insufficient Session Binding Allows SSE Stream Hijacking via Session ID Replay
High
CVE-2026-33946
was published
for
mcp
(RubyGems)
Mar 27, 2026
AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration
High
CVE-2026-33492
was published
for
wwbn/avideo
(Composer)
Mar 20, 2026
Rancher's Azure AD permission changes are not reflected on active sessions
High
CVE-2023-22648
was published
for
github.com/rancher/rancher
(Go)
Mar 3, 2026
FrankenPHP leaks session data between requests in worker mode
High
CVE-2026-24894
was published
for
github.com/dunglas/frankenphp
(Go)
Feb 12, 2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy...
High
Unreviewed
CVE-2026-22082
was published
Jan 9, 2026
All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows...
High
Unreviewed
CVE-2020-36913
was published
Jan 6, 2026
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53775
was published
Dec 11, 2025
Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53776
was published
Dec 11, 2025
Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to...
High
Unreviewed
CVE-2023-53741
was published
Dec 10, 2025
Session Fixation vulnerability in Rolantis Information Technologies Agentis allows Session...
High
Unreviewed
CVE-2025-10228
was published
Oct 14, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh...
High
Unreviewed
CVE-2025-42602
was published
Apr 23, 2025
When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables...
High
Unreviewed
CVE-2025-0126
was published
Apr 11, 2025
Mailcow through 2024-11b has a session fixation vulnerability in the web panel. It allows remote...
High
Unreviewed
CVE-2024-56529
was published
Jan 29, 2025
Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
High
CVE-2024-52553
was published
for
org.jenkins-ci.plugins:oic-auth
(Maven)
Nov 13, 2024
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7...
High
Unreviewed
CVE-2023-50176
was published
Nov 12, 2024
ProTip!
Advisories are also available from the
GraphQL API