GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
63 advisories
Filter by severity
A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions ...
High
Unreviewed
CVE-2024-35211
was published
Jun 11, 2024
Synology DiskStation Manager (DSM) before 6.2.3-25426-2 does not set the Secure flag for the...
Moderate
Unreviewed
CVE-2020-27650
was published
May 24, 2022
This vulnerability exists in the CP Plus Router due to insecure handling of cookie flags used...
High
Unreviewed
CVE-2025-0479
was published
Jan 20, 2025
Taipy has a Session Cookie without Secure and HTTPOnly flags
Moderate
CVE-2024-47833
was published
for
taipy
(pip)
Aug 27, 2024
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does...
Moderate
Unreviewed
CVE-2024-28771
was published
Jan 27, 2025
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does...
Moderate
Unreviewed
CVE-2024-28770
was published
Jan 27, 2025
A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking...
Moderate
Unreviewed
CVE-2025-24390
was published
Jan 27, 2025
General OpenMRS Security Advisory, January 2025: Penetration Testing Results and Patches
Critical
GHSA-vpxm-cr3r-pjp9
was published
for
org.openmrs.module:addresshierarchy
(Maven)
Jan 30, 2025
IBM PowerHA SystemMirror for i 7.4 and 7.5
does not set the secure attribute on authorization...
Moderate
Unreviewed
CVE-2024-55897
was published
Jan 4, 2025
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2024-39734
was published
Jul 14, 2024
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is...
Moderate
Unreviewed
CVE-2024-10718
was published
Mar 20, 2025
IBM Datacap 9.1.7, 9.1.8, and 9.1.9
does not set the secure attribute on authorization tokens...
Moderate
Unreviewed
CVE-2025-36026
was published
Jun 28, 2025
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker...
Moderate
Unreviewed
CVE-2025-27450
was published
Jul 3, 2025
This vulnerability exists in Digisol DG-GR6821AC Router due to misconfiguration of both Secure...
High
Unreviewed
CVE-2025-53757
was published
Jul 16, 2025
Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the...
Critical
Unreviewed
CVE-2025-8037
was published
Jul 22, 2025
IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2025-36011
was published
Sep 9, 2025
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue...
Moderate
Unreviewed
CVE-2025-52632
was published
Oct 10, 2025
HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious...
Low
Unreviewed
CVE-2025-52614
was published
Oct 12, 2025
Mattermost Server does not check if cookies are used over SSL
High
CVE-2016-11076
was published
for
github.com/mattermost/mattermost-server
(Go)
May 24, 2022
IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on...
Low
Unreviewed
CVE-2025-36249
was published
Oct 31, 2025
A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL...
Moderate
Unreviewed
CVE-2024-58317
was published
Dec 18, 2025
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web...
Moderate
Unreviewed
CVE-2026-1697
was published
Feb 26, 2026
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.8 and 6.1.0.0 through 6.1.2.3...
Moderate
Unreviewed
CVE-2023-42016
was published
Feb 9, 2024
@grackle-ai/server has a Missing Secure Flag on Session Cookie
Low
GHSA-5j35-xr4g-vwf4
was published
for
@grackle-ai/server
(npm)
Mar 25, 2026
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure...
Moderate
Unreviewed
CVE-2026-32745
was published
Mar 13, 2026
ProTip!
Advisories are also available from the
GraphQL API