GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
282 advisories
Filter by severity
Session fixation vulnerability in Rails
Moderate
CVE-2007-5380
was published
for
rails
(RubyGems)
Oct 24, 2017
rest-client Gem Vulnerable to Session Fixation
Critical
CVE-2015-1820
was published
for
rest-client
(RubyGems)
Aug 13, 2018
aiohttp-session Session Fixation vulnerability
Moderate
CVE-2018-1000519
was published
for
aiohttp-session
(pip)
Sep 13, 2018
Access and integrity issue within Eclipse Jetty
High
CVE-2018-12538
was published
for
org.eclipse.jetty:jetty-server
(Maven)
Oct 16, 2018
Improper Authentication in org.keycloak:keycloak-core
High
CVE-2016-8609
was published
for
org.keycloak:keycloak-core
(Maven)
Oct 18, 2018
Session Fixation in Apache Zeppelin
High
CVE-2017-12619
was published
for
org.apache.zeppelin:zeppelin
(Maven)
Apr 24, 2019
Session fixation in change password form
Moderate
CVE-2019-12203
was published
for
silverstripe/framework
(Composer)
Nov 12, 2019
In Apache Tomcat, when using FORM authentication there was a narrow window where an attacker could perform a session fixation attack
High
CVE-2019-17563
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Dec 26, 2019
Improper implementation of the session fixation protection in Infinispan
Critical
CVE-2019-10158
was published
for
org.infinispan:infinispan-core
(Maven)
Jan 21, 2020
Incorrect persistent NameID generation in SimpleSAMLphp
Critical
CVE-2017-12873
was published
for
simplesamlphp/simplesamlphp
(Composer)
Jan 24, 2020
Insufficient Session Expiration in Kiali
High
CVE-2020-1762
was published
for
github.com/kiali/kiali
(Go)
May 18, 2021
Session Fixation in Subrion CMS
Moderate
CVE-2020-12467
was published
for
intelliants/subrion
(Composer)
Jun 22, 2021
Cookie persistence after password changes in symfony/security-bundle
Moderate
CVE-2021-41268
was published
for
symfony/security-bundle
(Composer)
Nov 24, 2021
Session fixation in express-openid-connect
Moderate
CVE-2021-41246
was published
for
express-openid-connect
(npm)
Dec 9, 2021
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to...
High
Unreviewed
CVE-2021-31745
was published
Dec 11, 2021
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can...
High
Unreviewed
CVE-2021-44151
was published
Dec 14, 2021
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the...
Critical
Unreviewed
CVE-2021-20151
was published
Dec 31, 2021
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An...
High
Unreviewed
CVE-2022-22551
was published
Jan 22, 2022
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session...
High
Unreviewed
CVE-2021-39066
was published
Feb 3, 2022
Session Fixation in WildFly Elytron
High
CVE-2020-10714
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Feb 15, 2022
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable...
Critical
Unreviewed
CVE-2022-22922
was published
Feb 19, 2022
Shopware guest session is shared between customers
Moderate
CVE-2022-24745
was published
for
shopware/platform
(Composer)
Mar 10, 2022
ProTip!
Advisories are also available from the
GraphQL API