GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,291 advisories
Filter by severity
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege...
High
Unreviewed
CVE-2024-0865
was published
Jun 12, 2024
Hard-coded JWT secret allows authentication bypass in Veeam Recovery Orchestrator
Critical
Unreviewed
CVE-2024-29855
was published
Jun 11, 2024
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
Critical
Unreviewed
CVE-2024-1228
was published
Jun 10, 2024
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
Critical
Unreviewed
CVE-2024-3700
was published
Jun 10, 2024
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
Critical
Unreviewed
CVE-2024-3699
was published
Jun 10, 2024
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2023-49223
was published
Jun 7, 2024
Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the...
High
Unreviewed
CVE-2023-49224
was published
Jun 7, 2024
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public...
High
Unreviewed
CVE-2023-49222
was published
Jun 7, 2024
Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local...
High
Unreviewed
CVE-2023-49221
was published
Jun 7, 2024
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials...
High
Unreviewed
CVE-2024-29170
was published
Jun 4, 2024
TOTOLINK CP300 V2.0.4-B20201102 was discovered to contain a hardcoded password vulnerability in ...
Critical
Unreviewed
CVE-2024-36782
was published
Jun 3, 2024
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to...
High
Unreviewed
CVE-2024-32988
was published
May 22, 2024
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5...
High
Unreviewed
CVE-2024-4844
was published
May 16, 2024
Hard-coded credentials are used by the
CyberPower PowerPanel
platform to authenticate to the ...
Critical
Unreviewed
CVE-2024-32053
was published
May 15, 2024
Weak account password in GE HealthCare EchoPAC products
Critical
Unreviewed
CVE-2024-27107
was published
May 14, 2024
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device...
Critical
Unreviewed
CVE-2024-32740
was published
May 14, 2024
TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the...
High
Unreviewed
CVE-2024-34219
was published
May 14, 2024
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a hardcoded password for root at ...
Critical
Unreviewed
CVE-2024-31810
was published
May 14, 2024
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication...
High
Unreviewed
CVE-2024-23473
was published
May 14, 2024
Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST...
High
Unreviewed
CVE-2023-26566
was published
May 14, 2024
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2023-51629
was published
May 3, 2024
Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation...
High
Unreviewed
CVE-2023-51588
was published
May 3, 2024
D-Link D-View InstallApplication Use of Hard-coded Credentials Authentication Bypass...
Critical
Unreviewed
CVE-2023-44411
was published
May 3, 2024
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass...
Moderate
Unreviewed
CVE-2023-39458
was published
May 3, 2024
Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure...
Moderate
Unreviewed
CVE-2023-39482
was published
May 3, 2024
ProTip!
Advisories are also available from the
GraphQL API