GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,790
Erlang
36
GitHub Actions
29
Go
2,370
Maven
5,000+
npm
3,994
NuGet
720
pip
3,783
Pub
12
RubyGems
927
Rust
982
Swift
38
Unreviewed advisories
All unreviewed
5,000+
342 advisories
Filter by severity
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel...
Moderate
Unreviewed
CVE-2025-4407
was published
Jun 30, 2025
MICROSENS NMP Web+ contain JSON Web Tokens (JWT) that do not expire, which could allow an...
High
Unreviewed
CVE-2025-49152
was published
Jun 26, 2025
ash_authentication_phoenix has Insufficient Session Expiration
Low
CVE-2025-4754
was published
for
ash_authentication_phoenix
(Erlang)
Jun 17, 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0,...
Moderate
Unreviewed
CVE-2024-50562
was published
Jun 10, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2025-25019
was published
Jun 3, 2025
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could...
Moderate
Unreviewed
CVE-2025-33005
was published
Jun 1, 2025
Web sessions in the web interface of Palo Alto Networks Prisma® Cloud Compute Edition do not...
Low
Unreviewed
CVE-2025-0138
was published
May 14, 2025
A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),...
High
Unreviewed
CVE-2025-40566
was published
May 13, 2025
A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic....
Moderate
Unreviewed
CVE-2025-4528
was published
May 11, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
ZITADEL Allows IdP Intent Token Reuse
High
CVE-2025-46815
was published
for
github.com/zitadel/zitadel
(Go)
May 6, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
ALBEDO Telecom Net.Time - PTP/NTP clock (Serial No. NBC0081P) software release 1.4.4 is...
High
Unreviewed
CVE-2025-2185
was published
Apr 25, 2025
Due to improper JSON Web Tokens implementation an unauthenticated remote attacker can guess a...
High
Unreviewed
CVE-2021-47663
was published
Apr 24, 2025
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow...
Moderate
Unreviewed
CVE-2024-22351
was published
Apr 24, 2025
An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to...
High
Unreviewed
CVE-2025-28059
was published
Apr 18, 2025
IBM Sterling Connect:Direct Web Services 6.1.0, 6.2.0, and 6.3.0
does not invalidate session...
Moderate
Unreviewed
CVE-2024-45651
was published
Apr 18, 2025
IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7...
Moderate
Unreviewed
CVE-2024-49825
was published
Apr 14, 2025
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user...
Critical
Unreviewed
CVE-2025-24859
was published
Apr 14, 2025
Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain...
Low
Unreviewed
CVE-2025-30516
was published
Apr 14, 2025
Insufficient Session Expiration vulnerability in Progress Software Corporation Sitefinity under...
High
Unreviewed
CVE-2025-1968
was published
Apr 9, 2025
IBM Jazz Reporting Service 7.0.2 and 7.0.3 does not invalidate session after logout which could...
Moderate
Unreviewed
CVE-2024-25051
was published
Apr 2, 2025
A session management flaw in Nagios Network Analyzer 2024R1.0.3 allows an attacker to reuse...
Moderate
Unreviewed
CVE-2025-28132
was published
Apr 1, 2025
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and...
Low
Unreviewed
CVE-2025-2596
was published
Mar 26, 2025
ProTip!
Advisories are also available from the
GraphQL API