GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,504
Maven
5,000+
npm
4,149
NuGet
735
pip
3,949
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,290 advisories
Filter by severity
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows...
Critical
Unreviewed
CVE-2025-54455
was published
Jul 23, 2025
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows...
Critical
Unreviewed
CVE-2025-54454
was published
Jul 23, 2025
Use of Hard-coded Credentials vulnerability in PAVO Inc. PAVO Pay allows Read Sensitive Constants...
High
Unreviewed
CVE-2025-4130
was published
Jul 21, 2025
Use of hard-coded, the same among all vulnerable installations SQLite credentials vulnerability...
High
Unreviewed
CVE-2025-4049
was published
Jul 21, 2025
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized...
High
Unreviewed
CVE-2025-4569
was published
Jul 21, 2025
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized...
Moderate
Unreviewed
CVE-2025-4570
was published
Jul 21, 2025
Use of Hard-coded Credentials in TP-Link Archer C50 V3(
<=
180703)/V4(
<=
250117
)/V5(
...
Moderate
Unreviewed
CVE-2025-6982
was published
Jul 16, 2025
This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials...
Moderate
Unreviewed
CVE-2025-53754
was published
Jul 16, 2025
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN...
Moderate
Unreviewed
CVE-2025-53842
was published
Jul 16, 2025
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file...
Moderate
Unreviewed
CVE-2025-52363
was published
Jul 14, 2025
A vulnerability, which was classified as critical, has been found in LB-LINK BL-AC3600 1.0.22....
High
Unreviewed
CVE-2025-7564
was published
Jul 14, 2025
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent...
Critical
Unreviewed
CVE-2024-38648
was published
Jul 12, 2025
An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet...
Critical
Unreviewed
CVE-2025-7503
was published
Jul 11, 2025
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-7401
was published
Jul 11, 2025
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Corporation photovoltaic...
High
Unreviewed
CVE-2025-5023
was published
Jul 10, 2025
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by a Use of Hard-coded...
High
Unreviewed
CVE-2025-49551
was published
Jul 8, 2025
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing...
Critical
Unreviewed
CVE-2025-37103
was published
Jul 8, 2025
A vulnerability has been discovered in the firmware of Paxton Paxton10 before 4.6 SR6. The...
High
Unreviewed
CVE-2025-52492
was published
Jul 7, 2025
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
Critical
Unreviewed
CVE-2025-45813
was published
Jul 2, 2025
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified...
Critical
Unreviewed
CVE-2025-20309
was published
Jul 2, 2025
A hardcoded credential vulnerability exists in the Blue Angel Software Suite deployed on embedded...
Critical
Unreviewed
CVE-2025-34034
was published
Jun 26, 2025
D-Link DPH-400S/SE VoIP Phone v1.01 contains hardcoded provisioning variables, including...
Critical
Unreviewed
CVE-2025-45784
was published
Jun 18, 2025
Sitecore Experience Manager (XM) and Experience Platform (XP) versions 10.1 to 10.1.4 rev. 011974...
High
Unreviewed
CVE-2025-34509
was published
Jun 17, 2025
OpenC3 COSMOS v6.0.0 was discovered to contain hardcoded credentials for the Service Account.
Critical
Unreviewed
CVE-2025-28388
was published
Jun 13, 2025
The ArchiverSpaApi ASP.NET application uses a hard-coded JWT signing key. An unauthenticated...
High
Unreviewed
CVE-2025-35940
was published
Jun 10, 2025
ProTip!
Advisories are also available from the
GraphQL API