GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,300
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,427
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
115 advisories
Filter by severity
Django allows user sessions hijacking via an empty string in the session key
Moderate
CVE-2015-3982
was published
for
Django
(pip)
May 17, 2022
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable...
Moderate
Unreviewed
CVE-2024-22318
was published
Feb 9, 2024
Liferay Portal's account lockout does not invalidate existing user sessions
Moderate
CVE-2023-47798
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
Feb 8, 2024
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0....
Moderate
Unreviewed
CVE-2024-10158
was published
Oct 20, 2024
Umbraco CMS Has Incomplete Server Termination During Explicit Sign-Out
Moderate
CVE-2024-48929
was published
for
Umbraco.CMS
(NuGet)
Oct 22, 2024
In visitUris of Notification.java, there is a possible way to leak image data across user...
Moderate
Unreviewed
CVE-2023-21239
was published
Jul 13, 2023
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a...
Moderate
Unreviewed
CVE-2023-21238
was published
Jul 13, 2023
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation,...
Moderate
Unreviewed
CVE-2024-10318
was published
Nov 6, 2024
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The...
Moderate
Unreviewed
CVE-2021-3740
was published
Nov 15, 2024
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC...
Moderate
Unreviewed
CVE-2023-24477
was published
Aug 9, 2023
OpenStack Horizon Session Fixation
Moderate
CVE-2012-2144
was published
for
horizon
(pip)
May 17, 2022
Apache IoTDB Session Fixation vulnerability
Moderate
CVE-2022-38369
was published
for
apache-iotdb
(Maven)
Sep 6, 2022
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the...
Moderate
Unreviewed
CVE-2024-28144
was published
Dec 12, 2024
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful...
Moderate
Unreviewed
CVE-2023-34156
was published
Jun 19, 2023
Password Pusher Allows Session Token Interception Leading to Potential Hijacking
Moderate
CVE-2024-56733
was published
for
pwpush
(RubyGems)
Dec 30, 2024
ProTip!
Advisories are also available from the
GraphQL API