GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
55
Go
4,533
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,145
Rust
1,514
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
536 advisories
Filter by severity
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy...
High
Unreviewed
CVE-2026-73611
was published
Aug 13, 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
Moderate
Unreviewed
CVE-2026-66376
was published
Aug 12, 2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke...
High
Unreviewed
CVE-2026-17600
was published
Aug 7, 2026
When internal roles are removed from a user within the WSO2 product, the system fails to...
Moderate
Unreviewed
CVE-2025-12317
was published
Aug 7, 2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed...
Moderate
Unreviewed
CVE-2024-8995
was published
Aug 6, 2026
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens...
Low
Unreviewed
CVE-2025-12627
was published
Aug 6, 2026
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer...
Critical
Unreviewed
CVE-2026-60053
was published
Aug 5, 2026
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows...
High
Unreviewed
CVE-2026-39924
was published
Aug 5, 2026
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
High
Unreviewed
CVE-2026-71206
was published
Aug 5, 2026
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc....
Moderate
Unreviewed
CVE-2026-14465
was published
Aug 4, 2026
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management...
High
Unreviewed
CVE-2026-51953
was published
Aug 1, 2026
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable...
Moderate
Unreviewed
CVE-2026-14227
was published
Jul 30, 2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3...
Moderate
Unreviewed
CVE-2024-40683
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality...
Moderate
Unreviewed
CVE-2026-16970
was published
Jul 30, 2026
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability...
Moderate
Unreviewed
CVE-2026-66400
was published
Jul 29, 2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session...
High
Unreviewed
CVE-2026-14996
was published
Jul 28, 2026
Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, and group restrictions
High
CVE-2026-43983
was published
for
github.com/pocket-id/pocket-id/backend
(Go)
Jul 28, 2026
Open WebUI: Realtime endpoints accept Redis-revoked JWTs after signout/backchannel logout
High
CVE-2026-59219
was published
for
open-webui
(pip)
Jul 24, 2026
Insufficient session expiration vulnerability in Progress MOVEit Transfer.
This issue affects...
High
Unreviewed
CVE-2026-15967
was published
Jul 23, 2026
Question2Answer through 1.8.8 contains a session invalidation vulnerability that allows attackers...
Critical
Unreviewed
CVE-2026-64829
was published
Jul 22, 2026
Gitea Remember-Me Token Theft Not Invalidating Attacker Session
Critical
CVE-2026-56750
was published
for
code.gitea.io/gitea
(Go)
Jul 21, 2026
HCL MyCloud was affected with Concurrent Login Vulnerability. It may increase the risk of...
Low
Unreviewed
CVE-2026-56583
was published
Jul 21, 2026
SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when...
Moderate
Unreviewed
CVE-2026-63753
was published
Jul 20, 2026
A security vulnerability has been detected in django-oauth django-oauth-toolkit 3.3.0. This issue...
Moderate
Unreviewed
CVE-2026-16206
was published
Jul 19, 2026
PlaywrightCapture stored capture-specific configuration and runtime data as mutable class-level...
High
Unreviewed
CVE-2026-63175
was published
Jul 16, 2026
ProTip!
Advisories are also available from the
GraphQL API