GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,279
Erlang
31
GitHub Actions
21
Go
2,056
Maven
5,000+
npm
3,740
NuGet
668
pip
3,421
Pub
12
RubyGems
891
Rust
873
Swift
36
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
203 advisories
Filter by severity
Vulnerability of services denied by early fingerprint APIs on HarmonyOS products.Successful...
Moderate
Unreviewed
CVE-2023-34156
was published
Jun 19, 2023
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the...
Moderate
Unreviewed
CVE-2024-28144
was published
Dec 12, 2024
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login...
Critical
Unreviewed
CVE-2024-11317
was published
Dec 5, 2024
An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video...
High
Unreviewed
CVE-2023-34656
was published
Jun 29, 2023
The End-User Portal module before 1.0.65 for FreeScout sometimes allows an attacker to...
Critical
Unreviewed
CVE-2023-52268
was published
Nov 12, 2024
In certain conditions, depending on timing and the usage of the Chrome web browser, Guardian/CMC...
Moderate
Unreviewed
CVE-2023-24477
was published
Aug 9, 2023
A Session Fixation vulnerability exists in chatwoot/chatwoot versions prior to 2.4.0. The...
Moderate
Unreviewed
CVE-2021-3740
was published
Nov 15, 2024
A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7...
High
Unreviewed
CVE-2023-50176
was published
Nov 12, 2024
A session fixation issue was discovered in the NGINX OpenID Connect reference implementation,...
Moderate
Unreviewed
CVE-2024-10318
was published
Nov 6, 2024
In visitUris of Notification.java, there is a possible way to leak image data across user...
Moderate
Unreviewed
CVE-2023-21239
was published
Jul 13, 2023
In visitUris of RemoteViews.java, there is a possible leak of images between users due to a...
Moderate
Unreviewed
CVE-2023-21238
was published
Jul 13, 2023
In NetAdmin 4.0.30319, an attacker can steal a valid session cookie and inject it into another...
High
Unreviewed
CVE-2024-48955
was published
Oct 29, 2024
A vulnerability classified as problematic has been found in PHPGurukul Boat Booking System 1.0....
Moderate
Unreviewed
CVE-2024-10158
was published
Oct 20, 2024
Session Fixation vulnerability in Oceanic Software ValeApp allows Brute Force, Session Hijacking...
Critical
Unreviewed
CVE-2024-8643
was published
Sep 27, 2024
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable...
Moderate
Unreviewed
CVE-2024-22318
was published
Feb 9, 2024
The H2-DM1E PLC's authentication protocol appears to utilize either a custom encoding scheme or a...
High
Unreviewed
CVE-2024-45368
was published
Sep 13, 2024
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP2)....
Moderate
Unreviewed
CVE-2024-42345
was published
Sep 10, 2024
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive...
Low
Unreviewed
CVE-2023-45718
was published
Feb 10, 2024
IBM Aspera Shares 1.10.0 PL2 does not invalidate session after a password change which could...
Moderate
Unreviewed
CVE-2023-38018
was published
Aug 12, 2024
As of v1.5.0, the Argo web interface authentication system issued immutable tokens....
Moderate
Unreviewed
CVE-2020-8826
was published
May 24, 2022
An issue in Outline <= v0.76.1 allows attackers to execute a session hijacking attack via user...
High
Unreviewed
CVE-2024-37829
was published
Jul 9, 2024
A session fixation vulnerability in Bludit allows an attacker to bypass the server's...
Unknown
Unreviewed
CVE-2024-24552
was published
Jun 24, 2024
IBM Storage Scale 5.1.0.0 through 5.1.9.2 could allow an authenticated user to steal or...
Moderate
Unreviewed
CVE-2023-38002
was published
Apr 30, 2024
eQ-3 HomeMatic CCU3 firmware 3.41.11 allows session fixation. An attacker can create session IDs...
High
Unreviewed
CVE-2019-15849
was published
May 24, 2022
Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being...
Critical
Unreviewed
CVE-2023-0897
was published
Oct 26, 2023
ProTip!
Advisories are also available from the
GraphQL API