GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,150
NuGet
736
pip
3,952
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,327 advisories
Filter by severity
The firmware of all Wattsense Bridge devices contain the same hard-coded user and root...
Critical
Unreviewed
CVE-2025-26410
was published
Feb 11, 2025
All versions of the qBittorrent client through 4.5.5 use default credentials when the web user...
Critical
Unreviewed
CVE-2023-30801
was published
Oct 10, 2023
Use of Hard-coded Credentials vulnerability in GoodWe Technologies Co., Ltd. GW1500‑XS allows...
High
Unreviewed
CVE-2024-8893
was published
Feb 14, 2025
Rocket Software UniData versions prior to 8.2.4 build 3003 and UniVerse versions prior to 11.3.5...
Critical
Unreviewed
CVE-2023-28503
was published
Mar 29, 2023
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 client application...
High
Unreviewed
CVE-2024-52902
was published
Feb 19, 2025
SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the...
Moderate
Unreviewed
CVE-2024-28989
was published
Feb 11, 2025
Insecure AES key in Yealink Configuration Encrypt Tool below verrsion 1.2. A single, vendorwide,...
Critical
Unreviewed
CVE-2024-24681
was published
Feb 24, 2024
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the...
High
Unreviewed
CVE-2023-0391
was published
Mar 21, 2023
Use of Hard-coded Credentials, Storage of Sensitive Data in a Mechanism without Access Control...
High
Unreviewed
CVE-2024-9334
was published
Feb 27, 2025
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly...
Critical
Unreviewed
CVE-2024-51551
was published
Dec 5, 2024
TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 was discovered to contain a hardcoded...
Critical
Unreviewed
CVE-2024-57040
was published
Feb 27, 2025
SunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials....
Critical
Unreviewed
CVE-2024-50688
was published
Feb 26, 2025
An unauthenticated remote attacker can use hard-coded credentials to gain full administration...
Critical
Unreviewed
CVE-2025-1393
was published
Mar 5, 2025
A vulnerability was found in i-Drive i11 and i12 up to 20250227 and classified as problematic....
Low
Unreviewed
CVE-2025-1879
was published
Mar 3, 2025
Unitronics Unistream Unilogic – Versions prior to 1.35.227 -
CWE-259: Use of Hard-coded Password...
High
Unreviewed
CVE-2024-27774
was published
Mar 18, 2024
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege...
High
Unreviewed
CVE-2025-27255
was published
Mar 10, 2025
Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local...
Moderate
Unreviewed
CVE-2024-3130
was published
Apr 1, 2024
A hardcoded privileged ID within Lumisxp v15.0.x to v16.1.x allows attackers to bypass...
High
Unreviewed
CVE-2024-33329
was published
Jun 26, 2024
Prolink router PRS1841 was discovered to contain hardcoded credentials for its Telnet and FTP...
Critical
Unreviewed
CVE-2022-46637
was published
Feb 21, 2023
Zohocorp's ManageEngine Analytics Plus and Zoho Analytics on-premise versions older than 6130 are...
High
Unreviewed
CVE-2025-1724
was published
Mar 17, 2025
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote...
Low
Unreviewed
CVE-2019-17659
was published
Mar 17, 2025
IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root...
Moderate
Unreviewed
CVE-2024-57790
was published
Feb 14, 2025
An issue in the AsDB service of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to enumerate...
High
Unreviewed
CVE-2024-48125
was published
Jan 15, 2025
A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery...
Critical
Unreviewed
CVE-2025-2538
was published
Mar 20, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
ProTip!
Advisories are also available from the
GraphQL API