GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,248
Erlang
31
GitHub Actions
21
Go
2,016
Maven
5,000+
npm
3,721
NuGet
662
pip
3,400
Pub
11
RubyGems
890
Rust
852
Swift
36
Unreviewed advisories
All unreviewed
5,000+
128 advisories
Filter by severity
An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may...
Moderate
Unreviewed
CVE-2020-29012
was published
May 24, 2022
The vulnerability can be described as a failure to invalidate user session upon password change....
Moderate
Unreviewed
CVE-2021-35214
was published
May 24, 2022
IBM Sterling File Gateway User Interface 2.2.0.0 through 6.1.1.0 does not invalidate session...
Moderate
Unreviewed
CVE-2021-20473
was published
May 24, 2022
IBM i2 iBase 8.9.13 and 9.0.0 could allow a local attacker to obtain sensitive information due to...
Moderate
Unreviewed
CVE-2021-29868
was published
May 24, 2022
TYPO3 CMS vulnerable to Insufficient Session Expiration after Password Reset
Moderate
CVE-2022-23502
was published
for
typo3/cms
(Composer)
Dec 13, 2022
IBM Cloud Pak for Security 1.3.0.1(CP4S) does not invalidate session after logout which could...
Moderate
Unreviewed
CVE-2020-4696
was published
May 24, 2022
IBM InfoSphere Information Server 11.7 does not invalidate session after logout which could allow...
Moderate
Unreviewed
CVE-2022-41291
was published
Oct 7, 2022
devhub 0.102.0 was discovered to contain a broken session control.
Moderate
Unreviewed
CVE-2022-41542
was published
Oct 17, 2022
nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key...
Moderate
Unreviewed
CVE-2014-3616
was published
May 13, 2022
A vulnerability in the SRX Series Service Gateway allows deleted dynamic VPN users to establish...
Moderate
Unreviewed
CVE-2019-0015
was published
May 13, 2022
Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has...
Moderate
Unreviewed
CVE-2019-5641
was published
Sep 22, 2022
Server session is not invalidated when logout() helper method of Authentication module is used in Vaadin 18-19
Moderate
CVE-2021-31408
was published
for
com.vaadin:vaadin-bom
(Maven)
Apr 22, 2021
Insufficient Session Expiration and TOCTOU Race Condition in OPC FOundation UA .Net Standard
Moderate
CVE-2020-8867
was published
for
OPCFoundation.NetStandard.Opc.Ua
(NuGet)
Aug 2, 2021
XS Command-Line Interface (CLI) user sessions with the SAP HANA Extended Application Services (XS...
Moderate
Unreviewed
CVE-2018-2451
was published
May 13, 2022
Exploitation of session variables, resource IDs and other trusted credentials vulnerability in...
Moderate
Unreviewed
CVE-2017-3966
was published
May 13, 2022
The Milwaukee ONE-KEY Android mobile application uses bearer tokens with an expiration of one...
Moderate
Unreviewed
CVE-2017-3215
was published
May 13, 2022
An Insufficient Session Expiration issue was discovered in ProMinent MultiFLEX M10a Controller...
Moderate
Unreviewed
CVE-2017-14007
was published
May 13, 2022
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to...
Moderate
Unreviewed
CVE-2017-1000131
was published
May 13, 2022
IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2...
Moderate
Unreviewed
CVE-2019-4072
was published
May 24, 2022
"IBM MQ Appliance 9.2 CD, 9.2 LTS, 9.3 CD, and LTS 9.3 does not invalidate session after logout...
Moderate
Unreviewed
CVE-2022-40230
was published
Nov 4, 2022
A denial of service vulnerability exists in Schneider Electric's MiCOM Px4x (P540 range excluded)...
Moderate
Unreviewed
CVE-2018-7758
was published
May 14, 2022
Philips ISCV application prior to version 2.3.0 has an insufficient session expiration...
Moderate
Unreviewed
CVE-2018-5438
was published
May 14, 2022
IBM Integration Bus 9.0 and 10.0 could allow an attacker that has captured a valid session id to...
Moderate
Unreviewed
CVE-2017-1693
was published
May 14, 2022
Mahara 1.8 before 1.8.6 and 1.9 before 1.9.4 and 1.10 before 1.10.1 and 15.04 before 15.04.0 are...
Moderate
Unreviewed
CVE-2017-1000136
was published
May 17, 2022
Mahara 1.8 before 1.8.7 and 1.9 before 1.9.5 and 1.10 before 1.10.3 and 15.04 before 15.04.0 are...
Moderate
Unreviewed
CVE-2017-1000135
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API