GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
102
GitHub Actions
54
Go
4,340
Maven
5,000+
npm
5,000+
NuGet
1,033
pip
5,000+
Pub
13
RubyGems
1,122
Rust
1,498
Swift
61
Unreviewed advisories
All unreviewed
5,000+
62 advisories
Filter by severity
open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing...
Critical
Unreviewed
CVE-2026-56400
was published
Jul 15, 2026
Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component.
The camel...
Critical
Unreviewed
CVE-2026-46455
was published
Jul 6, 2026
Insufficient session expiration vulnerability in syslink software AG Avantra on Linux, Windows...
Critical
Unreviewed
CVE-2026-8670
was published
May 26, 2026
Apache Airflow: JWT token still valid after logout
Critical
CVE-2025-57735
was published
for
apache-airflow
(pip)
Apr 9, 2026
Vijkunja has Weak Password Policy Combined with Persistent Sessions After Password Change
Critical
CVE-2026-27575
was published
for
code.vikunja.io/api
(Go)
Feb 25, 2026
Not properly invalidated session vulnerability in Graylog Web Interface, version 2.2.3, due to...
Critical
Unreviewed
CVE-2026-1435
was published
Feb 18, 2026
Token leases could outlive their TTL in HashiCorp Vault
Critical
CVE-2020-25816
was published
for
github.com/hashicorp/vault
(Go)
May 24, 2022
Requarks Wiki.js 2.5.307 does not properly revoke or invalidate active JWT tokens when a user...
Critical
Unreviewed
CVE-2025-56643
was published
Nov 18, 2025
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user...
Critical
Unreviewed
CVE-2024-13996
was published
Oct 31, 2025
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.7.3, macOS...
Critical
Unreviewed
CVE-2025-24106
was published
Jan 28, 2025
On versions before 2.1.4, session is not invalidated after logout. When the user logged in...
Critical
Unreviewed
CVE-2024-29070
was published
Jul 23, 2024
A session management vulnerability exists in Apache Roller before version 6.1.5 where active user...
Critical
Unreviewed
CVE-2025-24859
was published
Apr 14, 2025
In affected versions of Octopus Server it is possible for a session token to be valid...
Critical
Unreviewed
CVE-2022-2782
was published
Oct 27, 2022
Fusiondirectory 1.3 suffers from Improper Session Handling.
Critical
Unreviewed
CVE-2022-36179
was published
Nov 22, 2022
Insufficient Session Expiration vulnerability in Drupal Persistent Login allows Forceful Browsing...
Critical
Unreviewed
CVE-2024-13280
was published
Jan 9, 2025
An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in...
Critical
Unreviewed
CVE-2021-35473
was published
Nov 11, 2024
SaltStack Salt eauth tokens can be used once after expiration
Critical
CVE-2021-3144
was published
for
salt
(pip)
May 24, 2022
Samly access control vulnerability
Critical
CVE-2024-25718
was published
for
Samly
(Erlang)
Feb 11, 2024
An attacker with access to the network where CIRCUTOR Q-SMT is located in its firmware version 1...
Critical
Unreviewed
CVE-2024-8888
was published
Sep 18, 2024
xzs-mysql 3.8 is vulnerable to Insufficient Session Expiration, which allows attackers to use the...
Critical
Unreviewed
CVE-2024-29401
was published
Mar 26, 2024
SurveyKing v1.3.1 was discovered to keep users' sessions active after logout. Related to an...
Critical
Unreviewed
CVE-2024-35049
was published
May 14, 2024
An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an...
Critical
Unreviewed
CVE-2023-28001
was published
Jul 11, 2023
In Siren Investigate before 13.2.2, session keys remain active even after logging out.
Critical
Unreviewed
CVE-2023-35857
was published
Jun 19, 2023
Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an...
Critical
Unreviewed
CVE-2019-11168
was published
May 24, 2022
Mastodon before 2.6.3 mishandles timeouts of incompletely established sessions.
Critical
Unreviewed
CVE-2018-21018
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API