GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,826
Erlang
36
GitHub Actions
32
Go
2,426
Maven
5,000+
npm
4,058
NuGet
723
pip
3,848
Pub
12
RubyGems
934
Rust
1,006
Swift
38
Unreviewed advisories
All unreviewed
5,000+
352 advisories
Filter by severity
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform...
Moderate
Unreviewed
CVE-2025-36040
was published
Jul 31, 2025
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car...
High
Unreviewed
CVE-2025-50486
was published
Jul 28, 2025
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online...
High
Unreviewed
CVE-2025-50485
was published
Jul 28, 2025
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood...
High
Unreviewed
CVE-2025-50487
was published
Jul 28, 2025
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM...
High
Unreviewed
CVE-2025-50484
was published
Jul 28, 2025
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank...
High
Unreviewed
CVE-2025-50491
was published
Jul 28, 2025
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online...
High
Unreviewed
CVE-2025-50488
was published
Jul 28, 2025
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain...
High
Unreviewed
CVE-2025-31952
was published
Jul 24, 2025
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4...
Moderate
Unreviewed
CVE-2024-27779
was published
Jul 18, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel...
Moderate
Unreviewed
CVE-2025-4407
was published
Jun 30, 2025
MICROSENS NMP Web+ contain JSON Web Tokens (JWT) that do not expire, which could allow an...
High
Unreviewed
CVE-2025-49152
was published
Jun 26, 2025
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0,...
Moderate
Unreviewed
CVE-2024-50562
was published
Jun 10, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2025-25019
was published
Jun 3, 2025
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could...
Moderate
Unreviewed
CVE-2025-33005
was published
Jun 1, 2025
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not...
Low
Unreviewed
CVE-2025-0138
was published
May 14, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),...
High
Unreviewed
CVE-2025-40566
was published
May 13, 2025
A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic....
Moderate
Unreviewed
CVE-2025-4528
was published
May 11, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is...
High
Unreviewed
CVE-2025-2185
was published
Apr 25, 2025
Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a...
High
Unreviewed
CVE-2021-47663
was published
Apr 24, 2025
ProTip!
Advisories are also available from the
GraphQL API