GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,614
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,254
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,031
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            332 advisories
        Filter by severity
        
      
      
    
                    
                      An issue was discovered in Appalti & Contratti 9.12.2. It allows Session Fixation. When a user...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-44788
                      
                      was published
                      Nov 22, 2022 
                    
                  
                    
                      A critical vulnerability was found in PHPGurukul User Registration & Login and User Management...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45949
                      
                      was published
                      Apr 28, 2025 
                    
                  
                    
                      A vulnerability was found in PHPGurukul Hostel Management System 2.1 in the /hostel/change...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-45953
                      
                      was published
                      Apr 28, 2025 
                    
                  
                    
                      This vulnerability exists in Meon KYC solutions due to improper handling of access and refresh...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-42602
                      
                      was published
                      Apr 23, 2025 
                    
                  
                    
                      Improper session management in the /login_ok.htm endpoint of DAEnetIP4 METO v1.25 allows...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-28242
                      
                      was published
                      Apr 18, 2025 
                    
                  
                    
                      Improper session management in Elber REBLE310 Firmware v5.5.1.R , Equipment Model: REBLE310/RX10...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-28238
                      
                      was published
                      Apr 18, 2025 
                    
                  
                    
                      Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-12965
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      A vulnerability in the web functionality of the Cisco Prime LAN Management Solution could allow...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-12225
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-4963
                      
                      was published
                      May 14, 2022 
                    
                  
                    
                      Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-0892
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-9125
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1,...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2017-5831
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      An OAuth session fixation vulnerability existed in the VPN login flow, where an attacker could...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2020-15679
                      
                      was published
                      Dec 22, 2022 
                    
                  
                    
                      Moodle Session Fixation vulnerability
                    
                      
  Moderate
                    
                
                      
                        CVE-2010-1613
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      May 13, 2022 
                    
                  
                    
                      When configured using SAML, a session fixation vulnerability in the GlobalProtect™ login enables...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0126
                      
                      was published
                      Apr 11, 2025 
                    
                  
                    
                      E-Mails exported as PDF were stored in a cache that did not consider specific session information...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-23193
                      
                      was published
                      May 6, 2024 
                    
                  
                    
                      Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2007-4188
                      
                      was published
                      May 1, 2022 
                    
                  
                    
                      In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-48955
                      
                      was published
                      Oct 29, 2024 
                    
                  
                    
                      Keycloak vulnerable to session hijacking via re-authentication
                    
                      
  Moderate
                    
                
                      
                        CVE-2023-6787
                      
                      was published
                        for
                        
                          org.keycloak:keycloak-services
                        
                        (Maven)
                      Apr 17, 2024 
                    
                  
                    
                      The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-26658
                      
                      was published
                      Mar 11, 2025 
                    
                  
                    
                      Moodle Session Fixation vulnerability
                    
                      
  Critical
                    
                
                      
                        CVE-2021-36394
                      
                      was published
                        for
                        
                          moodle/moodle
                        
                        (Composer)
                      Mar 6, 2023 
                    
                  
                    
                      Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27661
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      Mattermost fails to invalidate all active sessions when converting a user to a bot
                    
                      
  Low
                    
                
                      
                        CVE-2025-1412
                      
                      was published
                        for
                        
                          github.com/mattermost/mattermost/server/v8
                        
                        (Go)
                      Feb 24, 2025 
                    
                  
                    
                      IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages 
with Watson Assistant chat feature...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-49344
                      
                      was published
                      Feb 20, 2025 
                    
                  
                    
                      Session Fixation vulnerability in in function login in class.auth.php in osTicket through 1.16.2.
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-31888
                      
                      was published
                      Apr 6, 2023 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API