GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
117 advisories
Filter by severity
A CWE-613: Insufficient Session Expiration vulnerability exists that could allow an attacker...
High
Unreviewed
CVE-2023-28003
was published
Apr 18, 2023
Answer vulnerable to Insufficient Session Expiration
High
CVE-2023-1543
was published
for
github.com/answerdev/answer
(Go)
Mar 21, 2023
Insufficient Session Expiration in pretix
High
CVE-2023-27891
was published
for
pretix
(pip)
Mar 7, 2023
vantage6 refresh tokens do not expire
High
CVE-2023-23929
was published
for
vantage6
(pip)
Feb 28, 2023
Insufficient Session Expiration in Jenkins Azure AD Plugin
High
CVE-2023-24426
was published
for
org.jenkins-ci.plugins:azure-ad
(Maven)
Jan 26, 2023
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access...
High
Unreviewed
CVE-2022-43844
was published
Jan 5, 2023
rdiffweb vulnerable to Insufficient Session Expiration
High
CVE-2022-3362
was published
for
rdiffweb
(pip)
Nov 15, 2022
Apache Airflow may allow authenticated users who have been deactivated to continue using the UI or API
High
CVE-2022-41672
was published
for
apache-airflow
(pip)
Oct 7, 2022
By sending specific queries to the resolver, an attacker can cause named to crash.
High
Unreviewed
CVE-2022-3080
was published
Sep 22, 2022
Improper Access Control in GitHub repository namelessmc/nameless prior to v2.0.2.
High
Unreviewed
CVE-2022-2820
was published
Aug 16, 2022
A vulnerability has been identified in SIMATIC MV540 H (All versions < V3.3), SIMATIC MV540 S ...
High
Unreviewed
CVE-2022-33137
was published
Jul 13, 2022
Insufficient Session Expiration in Nakama
High
CVE-2022-2306
was published
for
github.com/heroiclabs/nakama
(Go)
Jul 6, 2022
** DISPUTED ** A vulnerability has been found in Microsoft O365 and classified as critical. The...
High
Unreviewed
CVE-2022-2076
was published
Jun 15, 2022
Insufficient Session Expiration in NocoDB
High
CVE-2022-2064
was published
for
nocodb
(npm)
Jun 14, 2022
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an...
High
Unreviewed
CVE-2021-25966
was published
May 24, 2022
Liferay Portal and Liferay DXP fails to invalidate password reset tokens after use
High
CVE-2021-33322
was published
for
com.liferay.portal:com.liferay.portal.impl
(Maven)
May 24, 2022
In ArangoDB, versions v3.7.6 through v3.8.3 are vulnerable to Insufficient Session Expiration....
High
Unreviewed
CVE-2021-25940
was published
May 24, 2022
Camaleon CMS Insufficient Session Expiration vulnerability
High
CVE-2021-25970
was published
for
camaleon_cms
(RubyGems)
May 24, 2022
A vulnerability in the web-based management interface of multiple Cisco Small Business Series...
High
Unreviewed
CVE-2021-34739
was published
May 24, 2022
An insufficient session expiration vulnerability exists in the "Fish | Hunt FL" iOS app version 3...
High
Unreviewed
CVE-2021-33982
was published
May 24, 2022
Affected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to...
High
Unreviewed
CVE-2021-39113
was published
May 24, 2022
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in...
High
Unreviewed
CVE-2021-35342
was published
May 24, 2022
Redmine 4.2.0 and 4.2.1 allow existing user sessions to continue upon enabling two-factor...
High
Unreviewed
CVE-2021-37156
was published
May 24, 2022
IBM Guardium Data Encryption (GDE) 3.0.0.2 and 4.0.0.4 does not invalidate session after logout...
High
Unreviewed
CVE-2021-20378
was published
May 24, 2022
Multiple vulnerabilities in the web-based management interface of Cisco Small Business 220 Series...
High
Unreviewed
CVE-2021-1542
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API