GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,466
Erlang
33
GitHub Actions
23
Go
2,167
Maven
5,000+
npm
3,830
NuGet
696
pip
3,508
Pub
12
RubyGems
910
Rust
906
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
83 advisories
Filter by severity
The Service Layer in SAP Business One, allows attackers to potentially gain unauthorized access...
Moderate
Unreviewed
CVE-2025-26658
was published
Mar 11, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages
with Watson Assistant chat feature...
Moderate
Unreviewed
CVE-2024-49344
was published
Feb 20, 2025
HCL iAutomate is affected by a session fixation vulnerability. An attacker could hijack a victim...
Moderate
Unreviewed
CVE-2024-42207
was published
Feb 5, 2025
A UAA configured with multiple identity zones, does not properly validate session information...
Moderate
Unreviewed
CVE-2025-22216
was published
Jan 31, 2025
An improper session validation allows an unauthenticated attacker to cause certain request...
Moderate
Unreviewed
CVE-2025-24502
was published
Jan 30, 2025
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this...
Moderate
Unreviewed
CVE-2024-42170
was published
Jan 11, 2025
HCL MyXalytics is affected by a session fixation vulnerability. Cyber-criminals can exploit this...
Moderate
Unreviewed
CVE-2024-42171
was published
Jan 11, 2025
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the...
Moderate
Unreviewed
CVE-2024-28144
was published
Dec 12, 2024
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The...
Moderate
Unreviewed
CVE-2021-3740
was published
Nov 15, 2024
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation,...
Moderate
Unreviewed
CVE-2024-10318
was published
Nov 6, 2024
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0....
Moderate
Unreviewed
CVE-2024-10158
was published
Oct 20, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2)....
Moderate
Unreviewed
CVE-2024-42345
was published
Sep 10, 2024
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could...
Moderate
Unreviewed
CVE-2023-38018
was published
Aug 12, 2024
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or...
Moderate
Unreviewed
CVE-2023-38002
was published
Apr 30, 2024
Dell Storage Resource Manager, 4.9.0.0 and below, contain(s) a Session Fixation Vulnerability in...
Moderate
Unreviewed
CVE-2024-0157
was published
Apr 12, 2024
A vulnerability was found in Bdtask Wholesale Inventory Management System up to 20240311. It has...
Moderate
Unreviewed
CVE-2024-2639
was published
Mar 19, 2024
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable...
Moderate
Unreviewed
CVE-2024-22318
was published
Feb 9, 2024
IBM PowerSC 1.3, 2.0, and 2.1 does not provide logout functionality, which could allow an...
Moderate
Unreviewed
CVE-2023-50941
was published
Feb 2, 2024
An issue was discovered on GL.iNet devices before version 4.5.0. They assign the same session ID...
Moderate
Unreviewed
CVE-2023-50920
was published
Jan 12, 2024
Versions of Puppet Enterprise prior to 2021.7.6 and 2023.5 contain a flaw which results in broken...
Moderate
Unreviewed
CVE-2023-5309
was published
Nov 7, 2023
Session Fixation in GitHub repository instantsoft/icms2 prior to 2.16.1.
Moderate
Unreviewed
CVE-2023-4649
was published
Aug 31, 2023
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC...
Moderate
Unreviewed
CVE-2023-24477
was published
Aug 9, 2023
In visitUris of Notification.java, there is a possible way to leak image data across user...
Moderate
Unreviewed
CVE-2023-21239
was published
Jul 13, 2023
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a...
Moderate
Unreviewed
CVE-2023-21238
was published
Jul 13, 2023
Session Fixation in GitHub repository fossbilling/fossbilling prior to 0.5.1.
Moderate
Unreviewed
CVE-2023-3394
was published
Jun 23, 2023
ProTip!
Advisories are also available from the
GraphQL API