GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
36 advisories
Filter by severity
CISA Thorium does not properly invalidate previously used tokens when resetting passwords. An...
Low
Unreviewed
CVE-2025-35433
was published
Sep 17, 2025
Fides' Admin UI User Password Change Does Not Invalidate Current Session
Low
CVE-2025-57766
was published
for
ethyca-fides
(pip)
Sep 8, 2025
Weblate has a long session expiry when verifying second factor
Low
CVE-2025-58352
was published
for
Weblate
(pip)
Sep 4, 2025
A vulnerability has been identified in SmartClient modules Opcenter QL Home (SC) (All versions >=...
Low
Unreviewed
CVE-2024-41985
was published
Aug 12, 2025
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not...
Low
Unreviewed
CVE-2025-0138
was published
May 14, 2025
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain...
Low
Unreviewed
CVE-2025-30516
was published
Apr 14, 2025
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and...
Low
Unreviewed
CVE-2025-2596
was published
Mar 26, 2025
Apache Airflow Fab Provider Insufficient Session Expiration vulnerability
Low
CVE-2024-45033
was published
for
apache-airflow-providers-fab
(pip)
Jan 8, 2025
In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which...
Low
Unreviewed
CVE-2024-7998
was published
Aug 21, 2024
An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and...
Low
Unreviewed
CVE-2022-45862
was published
Aug 13, 2024
Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
Low
CVE-2024-42447
was published
for
apache-airflow-providers-fab
(pip)
Aug 5, 2024
zenml-io/zenml does not expire the session after password reset
Low
CVE-2024-4680
was published
for
zenml
(pip)
Jun 8, 2024
silverstripe/framework's pre-existing alc_enc cookies log users in if remember me is disabled
Low
GHSA-5r8w-66hq-rc39
was published
for
silverstripe/framework
(Composer)
May 27, 2024
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive...
Low
Unreviewed
CVE-2023-45718
was published
Feb 10, 2024
A vulnerability was found in Totolink N200RE V5 9.3.5u.6255_B20211224. It has been classified as...
Low
Unreviewed
CVE-2024-0942
was published
Jan 26, 2024
A vulnerability was found in Totolink N350RT 9.3.5u.6255. It has been declared as problematic....
Low
Unreviewed
CVE-2024-0943
was published
Jan 26, 2024
A vulnerability was found in Totolink T8 4.1.5cu.833_20220905. It has been rated as problematic....
Low
Unreviewed
CVE-2024-0944
was published
Jan 26, 2024
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been rated as...
Low
Unreviewed
CVE-2024-0350
was published
Jan 10, 2024
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile...
Low
Unreviewed
CVE-2023-40732
was published
Sep 14, 2023
Insufficient Session Expiration in GitHub repository fossbilling/fossbilling prior to 0.5.5.
Low
Unreviewed
CVE-2023-4005
was published
Jul 31, 2023
Graylog user session is still usable after logout
Low
CVE-2023-41041
was published
for
org.graylog2:graylog2-server
(Maven)
Jul 6, 2023
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user...
Low
Unreviewed
CVE-2023-22591
was published
Mar 15, 2023
An insufficient session expiration vulnerability exists in the ArubaOS command line interface....
Low
Unreviewed
CVE-2023-22771
was published
Mar 1, 2023
Shopware has Insufficient Session Expiration in Administration
Low
CVE-2023-22732
was published
for
shopware/core
(Composer)
Jan 20, 2023
ProTip!
Advisories are also available from the
GraphQL API