GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,339
Erlang
31
GitHub Actions
22
Go
2,099
Maven
5,000+
npm
3,763
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
883
Swift
37
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
207 advisories
Filter by severity
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not renew a session variable...
Moderate
Unreviewed
CVE-2018-1485
was published
May 13, 2022
IBM BigFix Platform 9.2.0 through 9.2.14 and 9.5 through 9.5.9 does not set the secure attribute...
Moderate
Unreviewed
CVE-2018-1484
was published
May 13, 2022
IBM Jazz Foundation products could allow a user with physical access to the system to log in as...
Moderate
Unreviewed
CVE-2018-1492
was published
May 13, 2022
IBM Security Privileged Identity Manager Virtual Appliance 2.2.1 does not renew a session...
Moderate
Unreviewed
CVE-2018-1626
was published
May 13, 2022
IBM Security Access Manager Appliance 9.0.1.0, 9.0.2.0, 9.0.3.0, 9.0.4.0, and 9.0.5.0 does not...
Moderate
Unreviewed
CVE-2018-1804
was published
May 13, 2022
IBM Security Identity Governance and Intelligence 5.2 through 5.2.4.1 Virtual Appliance does not...
Moderate
Unreviewed
CVE-2018-1948
was published
May 13, 2022
IBM Security Identity Manager 7.0.1 Virtual Appliance does not invalidate session tokens when the...
Low
Unreviewed
CVE-2018-1962
was published
May 13, 2022
Improper Session Management in SAP Business Objects, 4.0, from 4.10, from 4.20, 4.30, CMC/BI...
High
Unreviewed
CVE-2018-2408
was published
May 13, 2022
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud...
High
Unreviewed
CVE-2018-2409
was published
May 13, 2022
Navarino Infinity is prone to session fixation attacks. The server accepts the session ID as a...
High
Unreviewed
CVE-2018-5385
was published
May 13, 2022
A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000,...
High
Unreviewed
CVE-2018-5465
was published
May 13, 2022
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or...
High
Unreviewed
CVE-2018-8852
was published
May 13, 2022
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed....
Moderate
Unreviewed
CVE-2019-3784
was published
May 13, 2022
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens...
High
Unreviewed
CVE-2019-11213
was published
May 13, 2022
Insufficient session authentication in web server for Intel(R) Data Center Manager SDK before...
High
Unreviewed
CVE-2019-0102
was published
May 13, 2022
A session fixation vulnerability in CA Privileged Access Manager 2.x allows remote attackers to...
High
Unreviewed
CVE-2018-9026
was published
May 13, 2022
In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time...
High
Unreviewed
CVE-2018-17199
was published
May 13, 2022
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1...
High
Unreviewed
CVE-2018-6434
was published
May 13, 2022
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed...
Moderate
Unreviewed
CVE-2008-3222
was published
May 1, 2022
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to...
High
Unreviewed
CVE-2007-4188
was published
May 1, 2022
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable...
Low
Unreviewed
CVE-2001-1534
was published
Apr 30, 2022
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
High
Unreviewed
CVE-1999-0428
was published
Apr 30, 2022
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after...
Critical
Unreviewed
CVE-2021-38869
was published
Apr 28, 2022
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to...
High
Unreviewed
CVE-2010-1434
was published
Apr 21, 2022
A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when...
Moderate
Unreviewed
CVE-2021-20324
was published
Apr 19, 2022
ProTip!
Advisories are also available from the
GraphQL API