GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
168 advisories
Filter by severity
Argo CD web terminal session doesn't expire
High
CVE-2023-40025
was published
for
github.com/argoproj/argo-cd/v2
(Go)
Aug 23, 2023
MICROSENS NMP Web+ contain JSON Web Tokens (JWT) that do not expire, which could allow an...
High
Unreviewed
CVE-2025-49152
was published
Jun 26, 2025
Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use
High
CVE-2021-33322
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
May 24, 2022
HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain...
High
Unreviewed
CVE-2025-31952
was published
Jul 24, 2025
Improper session invalidation in the component /library/change-password.php of PHPGurukul Online...
High
Unreviewed
CVE-2025-50488
was published
Jul 28, 2025
Improper session invalidation in the component /banker/change-password.php of PHPGurukul Bank...
High
Unreviewed
CVE-2025-50491
was published
Jul 28, 2025
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Small CRM...
High
Unreviewed
CVE-2025-50484
was published
Jul 28, 2025
Improper session invalidation in the component /bbdms/change-password.php of PHPGurukul Blood...
High
Unreviewed
CVE-2025-50487
was published
Jul 28, 2025
Improper session invalidation in the component /carrental/update-password.php of PHPGurukul Car...
High
Unreviewed
CVE-2025-50486
was published
Jul 28, 2025
Improper session invalidation in the component /crm/change-password.php of PHPGurukul Online...
High
Unreviewed
CVE-2025-50485
was published
Jul 28, 2025
File Browser’s insecure JWT handling can lead to session replay attacks after logout
High
CVE-2025-53826
was published
for
github.com/filebrowser/filebrowser
(Go)
Jul 16, 2025
Improper Authentication vulnerability in Microchip TimeProvider 4100 (login modules) allows...
High
Unreviewed
CVE-2024-43685
was published
Oct 4, 2024
Coder vulnerable to privilege escalation could lead to a cross workspace compromise
High
CVE-2025-58437
was published
for
github.com/coder/coder/v2
(Go)
Sep 5, 2025
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization...
High
Unreviewed
CVE-2024-33507
was published
Oct 14, 2025
The
equipment grants a JWT token for each connection in the timeline, but during an
active valid...
High
Unreviewed
CVE-2025-64386
was published
Oct 31, 2025
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the...
High
Unreviewed
CVE-2022-0996
was published
Mar 24, 2022
An issue was discovered in SchedMD Slurm 23.02.x and 23.11.x. There is Incorrect Access Control...
High
Unreviewed
CVE-2023-49935
was published
Dec 14, 2023
KSmserver in KDE Plasma Workspace (aka plasma-workspace) before 5.27.11.1 and 6.x before 6.0.5.1...
High
Unreviewed
CVE-2024-36041
was published
Jul 5, 2024
Nagios Fusion versions prior to R2.1 contain a vulnerability due to the application not requiring...
High
Unreviewed
CVE-2025-34269
was published
Oct 31, 2025
Flowise Fails to Invalidate Existing Sessions After Password Changes
High
GHSA-x7rp-qj2h-ghgw
was published
for
flowise
(npm)
Nov 14, 2025
nopCommerce v4.70 and prior, and version 4.80.3, does not invalidate session cookies after logout...
High
Unreviewed
CVE-2025-11699
was published
Dec 1, 2025
A vulnerability has been identified in Genexis Platinum P4410 router (Firmware P4410-V2–1.41)...
High
Unreviewed
CVE-2025-65883
was published
Dec 4, 2025
Pterodactyl does not revoke SFTP access when server is deleted or permissions reduced
High
CVE-2025-68954
was published
for
github.com/pterodactyl/wings
(Composer)
Jan 6, 2026
Insufficient Session Expiration vulnerability in ABB WebPro SNMP Card PowerValue, ABB WebPro SNMP...
High
Unreviewed
CVE-2025-4677
was published
Jan 7, 2026
This vulnerability occurs when the system permits multiple simultaneous
connections to the...
High
Unreviewed
CVE-2025-55705
was published
Jan 23, 2026
ProTip!
Advisories are also available from the
GraphQL API