GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,624
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
545 advisories
Filter by severity
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php,...
Critical
Unreviewed
CVE-2026-84480
was published
Sep 2, 2026
Memos versions 0.26.0 through 0.30.0 fail to revoke refresh tokens when a user changes their...
High
Unreviewed
CVE-2026-84203
was published
Sep 1, 2026
A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue...
Low
Unreviewed
CVE-2026-82909
was published
Aug 31, 2026
Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route...
Moderate
Unreviewed
CVE-2026-82469
was published
Aug 29, 2026
HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may...
Moderate
Unreviewed
CVE-2025-62342
was published
Aug 27, 2026
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for...
Moderate
Unreviewed
CVE-2026-73180
was published
Aug 26, 2026
Ech0 before 4.7.3 fails to properly revoke access tokens created with never-expire option,...
Critical
Unreviewed
CVE-2026-79664
was published
Aug 25, 2026
The extension fails to properly validate the expiration of a client-supplied JWT token, allowing...
Moderate
Unreviewed
CVE-2026-77130
was published
Aug 25, 2026
An unauthenticated remote attacker in possession of a valid session identifier is able to...
Critical
Unreviewed
CVE-2026-14950
was published
Aug 20, 2026
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy...
High
Unreviewed
CVE-2026-73611
was published
Aug 13, 2026
Credentials for a deleted user may remain valid for a short period under specific conditions.
Moderate
Unreviewed
CVE-2026-66376
was published
Aug 12, 2026
Sonatype Nexus Repository 3 did not immediately terminate a user's active login session or revoke...
High
Unreviewed
CVE-2026-17600
was published
Aug 7, 2026
When internal roles are removed from a user within the WSO2 product, the system fails to...
Moderate
Unreviewed
CVE-2025-12317
was published
Aug 7, 2026
Unused authorization codes issued to deleted users are not being properly invalidated or removed...
Moderate
Unreviewed
CVE-2024-8995
was published
Aug 6, 2026
The user impersonation flow in WSO2 Identity Server fails to properly manage refresh tokens...
Low
Unreviewed
CVE-2025-12627
was published
Aug 6, 2026
Insufficient Session Expiration vulnerability in Apache Answer.
This issue affects Apache Answer...
Critical
Unreviewed
CVE-2026-60053
was published
Aug 5, 2026
Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows...
High
Unreviewed
CVE-2026-39924
was published
Aug 5, 2026
Shiori's CheckToken function (internal/domains/auth.go) validates only the JWT's HMAC signature...
High
Unreviewed
CVE-2026-71206
was published
Aug 5, 2026
Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc....
Moderate
Unreviewed
CVE-2026-14465
was published
Aug 4, 2026
An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management...
High
Unreviewed
CVE-2026-51953
was published
Aug 1, 2026
An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable...
Moderate
Unreviewed
CVE-2026-14227
was published
Jul 30, 2026
IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3...
Moderate
Unreviewed
CVE-2024-40683
was published
Jul 30, 2026
The IRIS web application in version 2.4.26 and possibly others contains a logout functionality...
Moderate
Unreviewed
CVE-2026-16970
was published
Jul 30, 2026
Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability...
Moderate
Unreviewed
CVE-2026-66400
was published
Jul 29, 2026
IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session...
High
Unreviewed
CVE-2026-14996
was published
Jul 28, 2026
ProTip!
Advisories are also available from the
GraphQL API