GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
40 advisories
Filter by severity
IBM Maximo Application Suite 9.2, 9.1, and 9.0 does not set the secure attribute on authorization...
Moderate
Unreviewed
CVE-2026-15656
was published
Aug 5, 2026
HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which...
Moderate
Unreviewed
CVE-2024-23572
was published
Jul 17, 2026
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of...
Moderate
Unreviewed
CVE-2026-11956
was published
Jun 11, 2026
nebula-mesh: Session and OIDC state cookies lack the Secure attribute
Moderate
CVE-2026-48058
was published
for
github.com/juev/nebula-mesh
(Go)
Jun 10, 2026
Apache Airflow has a Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
Moderate
CVE-2026-41017
was published
for
apache-airflow
(pip)
Jun 1, 2026
Apache Shiro sends sensitive cookies in HTTPS session without 'Secure' attribute
Moderate
CVE-2026-43828
was published
for
org.apache.shiro:shiro-web
(Maven)
May 26, 2026
NocoDB: Refresh Token Cookie Set Without `secure` and `sameSite` Flags
Moderate
CVE-2026-46550
was published
for
nocodb
(npm)
May 21, 2026
Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow...
Moderate
Unreviewed
CVE-2026-22617
was published
Apr 16, 2026
IBM Maximo Application Suite 9.1, 9.0, 8.11, and 8.10 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2026-4820
was published
Apr 1, 2026
In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure...
Moderate
Unreviewed
CVE-2026-32745
was published
Mar 13, 2026
The Secure and SameSite attribute are missing in the GraphicalData web services and WebClient web...
Moderate
Unreviewed
CVE-2026-1697
was published
Feb 26, 2026
A cookie security configuration vulnerability in Kentico Xperience allows attackers to bypass SSL...
Moderate
Unreviewed
CVE-2024-58317
was published
Dec 18, 2025
A Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability in HCL AION.This issue...
Moderate
Unreviewed
CVE-2025-52632
was published
Oct 10, 2025
IBM Jazz for Service Management 1.1.3.0 through 1.1.3.24 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2025-36011
was published
Sep 9, 2025
The Secure attribute is missing on multiple cookies provided by the MEAC300-FNADE4. An attacker...
Moderate
Unreviewed
CVE-2025-27450
was published
Jul 3, 2025
IBM Datacap 9.1.7, 9.1.8, and 9.1.9
does not set the secure attribute on authorization tokens...
Moderate
Unreviewed
CVE-2025-36026
was published
Jun 28, 2025
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is...
Moderate
Unreviewed
CVE-2024-10718
was published
Mar 20, 2025
A vulnerability in OTRS Application Server and reverse proxy settings allows session hijacking...
Moderate
Unreviewed
CVE-2025-24390
was published
Jan 27, 2025
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does...
Moderate
Unreviewed
CVE-2024-28770
was published
Jan 27, 2025
IBM Security Directory Integrator 7.2.0 and IBM Security Verify Directory Integrator 10.0.0 does...
Moderate
Unreviewed
CVE-2024-28771
was published
Jan 27, 2025
IBM PowerHA SystemMirror for i 7.4 and 7.5
does not set the secure attribute on authorization...
Moderate
Unreviewed
CVE-2024-55897
was published
Jan 4, 2025
IBM Concert 1.0 does not set the secure attribute on authorization tokens or session cookies....
Moderate
Unreviewed
CVE-2024-43180
was published
Sep 13, 2024
Taipy has a Session Cookie without Secure and HTTPOnly flags
Moderate
CVE-2024-47833
was published
for
taipy
(pip)
Aug 27, 2024
This vulnerability exists in SyroTech SY-GPON-1110-WDONT Router due to missing secure flag for...
Moderate
Unreviewed
CVE-2024-41684
was published
Jul 26, 2024
IBM Datacap Navigator 9.1.5, 9.1.6, 9.1.7, 9.1.8, and 9.1.9 does not set the secure attribute on...
Moderate
Unreviewed
CVE-2024-39734
was published
Jul 14, 2024
ProTip!
Advisories are also available from the
GraphQL API