GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
287 advisories
Filter by severity
Session Fixation in Apache CXF
High
CVE-2017-5656
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
A vulnerability in the web management interface of Brocade Fabric OS versions before 8.2.1, 8.1...
High
Unreviewed
CVE-2018-6434
was published
May 13, 2022
Authentication library in TYPO3 vulnerable to session fixation
High
CVE-2009-0256
was published
for
typo3/cms
(Composer)
May 2, 2022
Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed...
Moderate
Unreviewed
CVE-2008-3222
was published
May 1, 2022
Session fixation vulnerability in Joomla! before 1.0.13 (aka Sunglow) allows remote attackers to...
High
Unreviewed
CVE-2007-4188
was published
May 1, 2022
mod_usertrack in Apache 1.3.11 through 1.3.20 generates session ID's using predictable...
Low
Unreviewed
CVE-2001-1534
was published
Apr 30, 2022
OpenSSL and SSLeay allow remote attackers to reuse SSL sessions and bypass access controls.
High
Unreviewed
CVE-1999-0428
was published
Apr 30, 2022
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after...
Critical
Unreviewed
CVE-2021-38869
was published
Apr 28, 2022
Joomla! Core is prone to a session fixation vulnerability. An attacker may leverage this issue to...
High
Unreviewed
CVE-2010-1434
was published
Apr 21, 2022
TYPO3 is vulnerable to Session Fixation
Moderate
CVE-2010-3671
was published
for
typo3/cms-install
(Composer)
Apr 21, 2022
A flaw was found in WildFly Elytron. A variation to the use of a session fixation exploit when...
Moderate
Unreviewed
CVE-2021-20324
was published
Apr 19, 2022
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface...
High
Unreviewed
CVE-2020-25152
was published
Apr 15, 2022
Shopware guest session is shared between customers
Moderate
CVE-2022-24745
was published
for
shopware/platform
(Composer)
Mar 10, 2022
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable...
Critical
Unreviewed
CVE-2022-22922
was published
Feb 19, 2022
Session Fixation in WildFly Elytron
High
CVE-2020-10714
was published
for
org.wildfly.security:wildfly-elytron
(Maven)
Feb 15, 2022
IBM Financial Transaction Manager 3.2.4 does not invalidate session any existing session...
High
Unreviewed
CVE-2021-39066
was published
Feb 3, 2022
DELL EMC AppSync versions 3.9 to 4.3 use GET request method with sensitive query strings. An...
High
Unreviewed
CVE-2022-22551
was published
Jan 22, 2022
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a flaw in the session management for the...
Critical
Unreviewed
CVE-2021-20151
was published
Dec 31, 2021
An issue was discovered in Reprise RLM 14.2. As the session cookies are small, an attacker can...
High
Unreviewed
CVE-2021-44151
was published
Dec 14, 2021
Session Fixation vulnerability in login.php in Pluck-CMS Pluck 4.7.15 allows an attacker to...
High
Unreviewed
CVE-2021-31745
was published
Dec 11, 2021
Session fixation in express-openid-connect
Moderate
CVE-2021-41246
was published
for
express-openid-connect
(npm)
Dec 9, 2021
Cookie persistence after password changes in symfony/security-bundle
Moderate
CVE-2021-41268
was published
for
symfony/security-bundle
(Composer)
Nov 24, 2021
Session Fixation in Subrion CMS
Moderate
CVE-2020-12467
was published
for
intelliants/subrion
(Composer)
Jun 22, 2021
ProTip!
Advisories are also available from the
GraphQL API