GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
118
GitHub Actions
56
Go
4,844
Maven
5,000+
npm
5,000+
NuGet
1,129
pip
5,000+
Pub
13
RubyGems
1,157
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
400 advisories
Filter by severity
social-auth-core has a Session Fixation issue
Moderate
CVE-2026-57179
was published
for
social-auth-core
(pip)
Sep 24, 2026
A vulnerability was determined in Mstfakts College-Management-System. This affects the function...
Low
Unreviewed
CVE-2026-95828
was published
Sep 23, 2026
webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads...
Moderate
Unreviewed
CVE-2026-79312
was published
Sep 22, 2026
Hatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState
High
CVE-2026-61687
was published
for
hatchet
(Go)
Sep 21, 2026
When a request to the Airflow core API carries both a session cookie and an explicit ...
Moderate
Unreviewed
CVE-2026-82355
was published
Sep 21, 2026
HUBzero CMS through 2.2.32 accepts session identifiers from query strings and request variables...
High
Unreviewed
CVE-2026-92984
was published
Sep 17, 2026
djust: SSE sessions are not bound to the authenticated user; the client-chosen session_id is the sole authorization capability (session hijack)
High
CVE-2026-61592
was published
for
djust
(pip)
Sep 16, 2026
Http4s: CookieJar middleware accepts arbitrary Set-Cookie domain
Moderate
CVE-2026-69214
was published
for
org.http4s:http4s-client_2.12
(Maven)
Sep 15, 2026
Session fixation vulnerability in Secomea GateManager (webserver module) allows Session Fixation....
High
Unreviewed
CVE-2026-1758
was published
Sep 15, 2026
A vulnerability was found in ningzichun Student Management System up to...
Low
Unreviewed
CVE-2026-86674
was published
Sep 8, 2026
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege...
High
Unreviewed
CVE-2026-76196
was published
Sep 8, 2026
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management &...
Low
Unreviewed
CVE-2026-86279
was published
Sep 7, 2026
An issue in HubCore v.14.1.1 allows a remote attacker to escalate privileges via the HUBCOREID...
Critical
Unreviewed
CVE-2026-75171
was published
Sep 4, 2026
MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom...
High
Unreviewed
CVE-2026-85238
was published
Sep 3, 2026
In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, Jenkins does not rotate the session when a...
High
Unreviewed
CVE-2026-84652
was published
Sep 2, 2026
IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could...
Critical
Unreviewed
CVE-2026-18527
was published
Aug 29, 2026
Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s...
Critical
Unreviewed
CVE-2026-81826
was published
Aug 27, 2026
Ghost: Session Fixation in Ghost Admin
Moderate
CVE-2026-70594
was published
for
ghost
(npm)
Aug 4, 2026
Guzzle: Noncanonical cookie domain keeps subdomain scope
Moderate
CVE-2026-69245
was published
for
guzzlehttp/guzzle
(Composer)
Aug 3, 2026
The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the...
High
Unreviewed
CVE-2026-16496
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API...
Critical
Unreviewed
CVE-2021-32088
was published
Jul 28, 2026
Guzzle: Cookie Disclosure and Injection via IP-Address Domains
Moderate
CVE-2026-59883
was published
for
guzzlehttp/guzzle
(Composer)
Jul 20, 2026
A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue...
Moderate
Unreviewed
CVE-2026-16089
was published
Jul 17, 2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive...
Low
Unreviewed
CVE-2026-14609
was published
Jul 3, 2026
SurrealDB: HTTP /rpc `sessions` method leaks attached session UUIDs, enabling full session hijack by anonymous callers
High
GHSA-5qfp-32cf-69jh
was published
for
surrealdb
(Rust)
Jul 1, 2026
ProTip!
Advisories are also available from the
GraphQL API