GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,963
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,615
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,036
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,049
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
      21 advisories
        Filter by severity
        
      
      
    
                    
                      CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-35433
                      
                      was published
                      Sep 17, 2025 
                    
                  
                    
                      A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-41985
                      
                      was published
                      Aug 12, 2025 
                    
                  
                    
                      Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-0138
                      
                      was published
                      May 14, 2025 
                    
                  
                    
                      Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-30516
                      
                      was published
                      Apr 14, 2025 
                    
                  
                    
                      Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2596
                      
                      was published
                      Mar 26, 2025 
                    
                  
                    
                      In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-7998
                      
                      was published
                      Aug 21, 2024 
                    
                  
                    
                      An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-45862
                      
                      was published
                      Aug 13, 2024 
                    
                  
                    
                      Sametime is impacted by a failure to invalidate sessions.  The application is setting sensitive...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-45718
                      
                      was published
                      Feb 10, 2024 
                    
                  
                    
                      A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0944
                      
                      was published
                      Jan 26, 2024 
                    
                  
                    
                      A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0942
                      
                      was published
                      Jan 26, 2024 
                    
                  
                    
                      A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0943
                      
                      was published
                      Jan 26, 2024 
                    
                  
                    
                      A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-0350
                      
                      was published
                      Jan 10, 2024 
                    
                  
                    
                      A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-40732
                      
                      was published
                      Sep 14, 2023 
                    
                  
                    
                      Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-4005
                      
                      was published
                      Jul 31, 2023 
                    
                  
                    
                      IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-22591
                      
                      was published
                      Mar 15, 2023 
                    
                  
                    
                      An insufficient session expiration vulnerability exists in the ArubaOS command line interface....
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2023-22771
                      
                      was published
                      Mar 1, 2023 
                    
                  
                    
                      In Kibana versions before 7.12.0 and 6.8.15 a flaw in the session timeout was discovered where...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-22136
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2020-6197
                      
                      was published
                      May 24, 2022 
                    
                  
                    
                      IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2016-0234
                      
                      was published
                      May 13, 2022 
                    
                  
                    
                      HCL Commerce is affected by an Insufficient Session Expiration vulnerability. After the session...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2021-27751
                      
                      was published
                      May 7, 2022 
                    
                  
                    
                      Improper session management vulnerability in Samsung Health prior to 6.20.1.005 prevents logging...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2022-22283
                      
                      was published
                      Jan 11, 2022 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API