GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,534
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
536 advisories
Filter by severity
listmonk's active sessions remain valid after password reset and password change
High
CVE-2026-34828
was published
for
github.com/knadh/listmonk
(Go)
Apr 1, 2026
CI4MS: Account Deactivation Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34572
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
CI4MS: Account Deletion Module Grants Full Persistent Unauthorized Access for All‑Roles via Improper Session Invalidation (Logic Flaw)
High
CVE-2026-34570
was published
for
ci4-cms-erp/ci4ms
(Composer)
Apr 1, 2026
OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
CVE-2026-34503
was published
for
openclaw
(npm)
Mar 31, 2026
Duplicate Advisory: OpenClaw's device removal and token revocation do not terminate active WebSocket sessions
High
GHSA-89hr-6x2p-8xjv
was published
for
openclaw
(npm)
Mar 31, 2026
•
withdrawn
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
Moderate
CVE-2026-34362
was published
for
wwbn/avideo
(Composer)
Mar 30, 2026
Fleet: Password reset tokens remain valid after password change for 24 hours
Moderate
CVE-2026-26060
was published
for
github.com/fleetdm/fleet/v4
(Go)
Mar 27, 2026
HCL Aftermarket DPC is affected by Failure to Invalidate Session on Password Change will allow...
Moderate
Unreviewed
CVE-2025-55264
was published
Mar 26, 2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 does not invalidate a session after...
Moderate
Unreviewed
CVE-2025-14810
was published
Mar 25, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-27649
was published
Mar 21, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-32663
was published
Mar 21, 2026
Non-working logout functionality in Truesec’s LAPSWebUI before version 2.4 allows an attacker...
Moderate
Unreviewed
CVE-2025-15553
was published
Mar 16, 2026
Insufficient Session Expiration in Truesec’s LAPSWebUI before version 2.4 allows an attacker with...
Moderate
Unreviewed
CVE-2025-15552
was published
Mar 16, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-27764
was published
Mar 6, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-20748
was published
Mar 6, 2026
The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows...
Moderate
Unreviewed
CVE-2026-24912
was published
Mar 6, 2026
OliveTin Session Fixation: Logout Fails to Invalidate Server-Side Session
Moderate
CVE-2026-30224
was published
for
github.com/OliveTin/OliveTin
(Go)
Mar 5, 2026
2N Access Commander version 3.4.2 and prior improperly invalidates session tokens, allowing...
Moderate
Unreviewed
CVE-2025-59786
was published
Mar 4, 2026
NocoDB's Refresh Tokens Not Revoked on Password Reset
Moderate
CVE-2026-28396
was published
for
nocodb
(npm)
Mar 2, 2026
A weakness has been identified in SourceCodester Web-based Pharmacy Product Management System 1.0...
Low
Unreviewed
CVE-2026-3401
was published
Mar 2, 2026
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but...
High
Unreviewed
CVE-2026-27647
was published
Feb 27, 2026
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but...
High
Unreviewed
CVE-2026-26290
was published
Feb 27, 2026
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but...
High
Unreviewed
CVE-2026-25711
was published
Feb 27, 2026
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but...
High
Unreviewed
CVE-2026-25778
was published
Feb 27, 2026
The WebSocket backend uses charging station identifiers to uniquely
associate sessions but...
High
Unreviewed
CVE-2026-27652
was published
Feb 27, 2026
ProTip!
Advisories are also available from the
GraphQL API