GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,373
Erlang
33
GitHub Actions
22
Go
2,135
Maven
5,000+
npm
3,797
NuGet
687
pip
3,478
Pub
12
RubyGems
896
Rust
897
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,208 advisories
Filter by severity
HI-SCAN 6040i Hitrax HX-03-19-I was discovered to contain hardcoded credentials for access to...
Critical
Unreviewed
CVE-2024-48126
was published
Jan 15, 2025
ECOVACS robot lawnmowers and vacuums use a deterministic root password generated based on model...
High
Unreviewed
CVE-2024-11147
was published
Jan 23, 2025
INPRAX "iZZi connect" application on Android contains hard-coded MQTT queue credentials. The same...
Critical
Unreviewed
CVE-2024-0390
was published
Feb 15, 2024
Shenzen Tenda Technology IP Camera CP3 V11.10.00.2211041355 was discovered to contain a hard...
High
Unreviewed
CVE-2023-30351
was published
May 10, 2023
Flawed token generation implementation & Hard-coded key implementation
Moderate
Unreviewed
CVE-2024-55927
was published
Jan 23, 2025
AutoLib Software Systems OPAC v20.10 was discovered to have multiple API keys exposed within the...
High
Unreviewed
CVE-2024-48310
was published
Jan 29, 2025
An issue was discovered in DTEX DEC-M (DTEX Forwarder) 6.1.1. The com.dtexsystems.helper service,...
High
Unreviewed
CVE-2024-55968
was published
Jan 29, 2025
Zoho ManageEngine ADSelfService Plus before 6122 allows an authenticated user to achieve remote...
High
Unreviewed
CVE-2022-28810
was published
Apr 19, 2022
A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2...
Critical
Unreviewed
CVE-2023-37936
was published
Jan 14, 2025
Static credentials exist in the PostgreSQL data used in ManageEngine Access Manager Plus (AMP)...
High
Unreviewed
CVE-2023-2291
was published
Apr 26, 2023
EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0 are vulnerable to privilege escalation as the...
Critical
Unreviewed
CVE-2024-53356
was published
Feb 1, 2025
In EasyVirt DCScope <=8.6.0 and CO2Scope <=1.3.0, the AES encryption keys used to encrypt...
High
Unreviewed
CVE-2024-53357
was published
Feb 1, 2025
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all...
Low
Unreviewed
CVE-2024-50564
was published
Jan 14, 2025
Brocade SANnav OVA before v2.3.1, and v2.3.0a, contain hardcoded keys used by Docker to reach...
High
Unreviewed
CVE-2024-29963
was published
Apr 19, 2024
In the Brocade SANnav server versions before v2.3.1 and v2.3.0a, the SSH keys inside the OVA...
High
Unreviewed
CVE-2024-29960
was published
Apr 19, 2024
Brocade SANnav OVA before v2.3.1 and v2.3.0a contain hard-coded credentials in the documentation...
High
Unreviewed
CVE-2024-29966
was published
Apr 19, 2024
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability...
Moderate
Unreviewed
CVE-2024-48007
was published
Dec 13, 2024
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded...
Moderate
Unreviewed
CVE-2020-8657
was published
May 24, 2022
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB...
Critical
Unreviewed
CVE-2024-51547
was published
Feb 6, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that...
Moderate
Unreviewed
CVE-2024-50692
was published
Jan 25, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be...
Moderate
Unreviewed
CVE-2024-50690
was published
Jan 25, 2025
Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h, and Forever...
Critical
Unreviewed
CVE-2024-36556
was published
Feb 6, 2025
ONTAP Select Deploy administration utility versions 9.12.1.x,
9.13.1.x and 9.14.1.x contain hard...
Moderate
Unreviewed
CVE-2024-21990
was published
Apr 17, 2024
Hardcoded credentials in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to...
High
Unreviewed
CVE-2024-46436
was published
Feb 10, 2025
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated...
High
Unreviewed
CVE-2024-46429
was published
Feb 10, 2025
ProTip!
Advisories are also available from the
GraphQL API