GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
1,291 advisories
Filter by severity
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5...
High
Unreviewed
CVE-2022-29060
was published
Jul 20, 2022
This vulnerability affects all of the company's products that also include the FW versions:...
High
Unreviewed
CVE-2022-30627
was published
Jul 19, 2022
Disclosure of information - the system allows you to view usernames and passwords without...
High
Unreviewed
CVE-2022-30622
was published
Jul 18, 2022
libnx_apl.so on Nexans FTTO GigaSwitch before 6.02N and 7.x before 7.02 implements a Backdoor...
Critical
Unreviewed
CVE-2022-32985
was published
Jul 18, 2022
An issue was discovered in Infiray IRAY-A8Z3 1.0.957. The binary file /usr/local/sbin/webproject...
Critical
Unreviewed
CVE-2022-31210
was published
Jul 18, 2022
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This...
High
Unreviewed
CVE-2022-32389
was published
Jul 15, 2022
IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password...
High
Unreviewed
CVE-2020-4157
was published
Jul 13, 2022
IBM SiteProtector Appliance 3.1.1 contains hard-coded credentials, such as a password or...
Critical
Unreviewed
CVE-2020-4150
was published
Jul 12, 2022
The firmware of EDIMAX IC-3140W Version 3.11 is hardcoded with Administrator username and password.
Critical
Unreviewed
CVE-2021-40597
was published
Jun 30, 2022
Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller...
High
Unreviewed
CVE-2022-30997
was published
Jun 29, 2022
An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code...
Critical
Unreviewed
CVE-2022-34005
was published
Jun 20, 2022
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the...
High
Unreviewed
CVE-2020-36547
was published
Jun 18, 2022
Proietti Tech srl Planet Time Enterprise 4.2.0.1,4.2.0.0,4.1.0.0,4.0.0.0,3.3.1.0,3.3.0.0 is...
Critical
Unreviewed
CVE-2022-30422
was published
Jun 18, 2022
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter...
High
Unreviewed
CVE-2022-31619
was published
Jun 15, 2022
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum...
High
Unreviewed
CVE-2022-26476
was published
Jun 15, 2022
Rakuten Casa version AP_F_V1_4_1 or AP_F_V2_0_0 uses a hard-coded credential which may allow a...
Critical
Unreviewed
CVE-2022-29525
was published
Jun 14, 2022
A vulnerability was found in SICUNET Access Controller 0.32-05z. It has been classified as very...
Critical
Unreviewed
CVE-2017-20039
was published
Jun 12, 2022
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES...
Moderate
Unreviewed
CVE-2022-25807
was published
Jun 10, 2022
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES...
High
Unreviewed
CVE-2022-25806
was published
Jun 10, 2022
In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can start telnet without authorization because the...
Moderate
Unreviewed
CVE-2021-42892
was published
Jun 4, 2022
** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary...
High
Unreviewed
CVE-2022-29778
was published
Jun 4, 2022
USR IOT 4G LTE Industrial Cellular VPN Router v1.0.36 was discovered to contain hard-coded...
Critical
Unreviewed
CVE-2022-29730
was published
Jun 3, 2022
LinkPlay Sound Bar v1.0 allows attackers to escalate privileges via a hardcoded password for the...
Critical
Unreviewed
CVE-2022-28605
was published
Jun 3, 2022
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password ...
High
Unreviewed
CVE-2022-31462
was published
Jun 3, 2022
Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded...
High
Unreviewed
CVE-2022-31460
was published
Jun 3, 2022
ProTip!
Advisories are also available from the
GraphQL API