GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,670
Maven
5,000+
npm
4,296
NuGet
760
pip
4,075
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
166 advisories
Filter by severity
authentik's invitation expiry is delayed by at least 5 minutes
Moderate
CVE-2025-64708
was published
for
goauthentik.io
(Go)
Nov 19, 2025
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is...
Moderate
Unreviewed
CVE-2025-63226
was published
Nov 18, 2025
On affected platforms, if SSH session multiplexing was configured on the client side, SSH...
Moderate
Unreviewed
CVE-2025-54547
was published
Oct 30, 2025
Logout Functionality not Working.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1...
Moderate
Unreviewed
CVE-2025-12278
was published
Oct 26, 2025
Keycloak does not invalidate offline sessions when the offline_access scope is removed
Moderate
CVE-2025-12110
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Keycloak does not invalidate sessions when "Remember Me" is disabled
Moderate
CVE-2025-11429
was published
for
org.keycloak:keycloak-services
(Maven)
Oct 23, 2025
Strapi is vulnerable to Insufficient Session Expiration
Moderate
CVE-2025-3930
was published
for
@strapi/strapi
(npm)
Oct 16, 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.6.0 through 7.6.2...
Moderate
Unreviewed
CVE-2025-25252
was published
Oct 14, 2025
IBM Transformation Extender Advanced 10.0.1
does not invalidate session after logout which...
Moderate
Unreviewed
CVE-2023-49881
was published
Oct 1, 2025
Liferay Portal and DXP does not properly expire sessions
Moderate
CVE-2025-43819
was published
for
com.liferay:com.liferay.saml.impl
(Maven)
Sep 24, 2025
Insufficient Session Expiration (CWE-613) in the Web Admin Panel in AxxonSoft Axxon One prior to...
Moderate
Unreviewed
CVE-2025-10223
was published
Sep 10, 2025
Payload does not invalidate JWTs after log out
Moderate
CVE-2025-4643
was published
for
@payloadcms/graphql
(npm)
Aug 29, 2025
IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform...
Moderate
Unreviewed
CVE-2025-36040
was published
Jul 31, 2025
An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4...
Moderate
Unreviewed
CVE-2024-27779
was published
Jul 18, 2025
Insufficient Session Expiration vulnerability in ABB Lite Panel Pro.This issue affects Lite Panel...
Moderate
Unreviewed
CVE-2025-4407
was published
Jun 30, 2025
An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0,...
Moderate
Unreviewed
CVE-2024-50562
was published
Jun 10, 2025
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0...
Moderate
Unreviewed
CVE-2025-25019
was published
Jun 3, 2025
IBM Planning Analytics Local 2.0 and 2.1 does not invalidate session after a logout which could...
Moderate
Unreviewed
CVE-2025-33005
was published
Jun 1, 2025
The TeleMessage service through 2025-05-05 implements authentication through a long-lived...
Moderate
Unreviewed
CVE-2025-48929
was published
May 28, 2025
A suspended or recently logged-out user could continue to interact with Blueframe until the time...
Moderate
Unreviewed
CVE-2025-46741
was published
May 12, 2025
A vulnerability was found in Dígitro NGC Explorer up to 3.44.15 and classified as problematic....
Moderate
Unreviewed
CVE-2025-4528
was published
May 11, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-46336
was published
for
rack-session
(RubyGems)
May 8, 2025
Rack session gets restored after deletion
Moderate
CVE-2025-32441
was published
for
rack
(RubyGems)
May 8, 2025
Auth0 NextJS SDK v4 Missing Session Invalidation
Moderate
CVE-2025-46344
was published
for
@auth0/nextjs-auth0
(npm)
Apr 29, 2025
IBM InfoSphere Information 11.7 Server does not invalidate session after logout which could allow...
Moderate
Unreviewed
CVE-2024-22351
was published
Apr 24, 2025
ProTip!
Advisories are also available from the
GraphQL API