GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
379 advisories
Filter by severity
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is...
Moderate
Unreviewed
CVE-2025-63226
was published
Nov 18, 2025
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user...
Critical
Unreviewed
CVE-2025-56643
was published
Nov 18, 2025
Flowise Fails to Invalidate Existing Sessions After Password Changes
High
GHSA-x7rp-qj2h-ghgw
was published
for
flowise
(npm)
Nov 14, 2025
The
equipment grants a JWT token for each connection in the timeline, but during an
active valid...
High
Unreviewed
CVE-2025-64386
was published
Oct 31, 2025
Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring...
High
Unreviewed
CVE-2025-34269
was published
Oct 31, 2025
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user...
Critical
Unreviewed
CVE-2024-13996
was published
Oct 31, 2025
On affected platforms, if SSH session multiplexing was configured on the client side, SSH...
Moderate
Unreviewed
CVE-2025-54547
was published
Oct 30, 2025
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1...
Moderate
Unreviewed
CVE-2025-12278
was published
Oct 26, 2025
Keycloak does not invalidate offline sessions when the offline_access scope is removed
Moderate
CVE-2025-12110
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak does not invalidate sessions when "Remember Me" is disabled
Moderate
CVE-2025-11429
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Strapi is vulnerable to Insufficient Session Expiration
Moderate
CVE-2025-3930
was published
for
@strapi/strapi
(npm)
Oct 16, 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2...
Moderate
Unreviewed
CVE-2025-25252
was published
Oct 14, 2025
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization...
High
Unreviewed
CVE-2024-33507
was published
Oct 14, 2025
IBM Transformation Extender Advanced 10.0.1
does not invalidate session after logout which...
Moderate
Unreviewed
CVE-2023-49881
was published
Oct 1, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An...
Low
Unreviewed
CVE-2025-35433
was published
Sep 17, 2025
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to...
Moderate
Unreviewed
CVE-2025-10223
was published
Sep 10, 2025
Fides' Admin UI User Password Change Does Not Invalidate Current Session
Low
CVE-2025-57766
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
Weblate has a long session expiry when verifying second factor
Low
CVE-2025-58352
was published
for
Weblate
(pip)
Sep 4, 2025
Payload does not invalidate JWTs after log out
Moderate
CVE-2025-4643
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Low
Unreviewed
CVE-2024-41985
was published
Aug 12, 2025
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform...
Moderate
Unreviewed
CVE-2025-36040
was published
Jul 31, 2025
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car...
High
Unreviewed
CVE-2025-50486
was published
Jul 28, 2025
ProTip!
Advisories are also available from the
GraphQL API