GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,726
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,570
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
721 advisories
Filter by severity
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or...
Critical
Unreviewed
CVE-2026-13446
was published
Jul 17, 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Critical
CVE-2026-55579
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing...
Critical
Unreviewed
CVE-2026-14807
was published
Jul 6, 2026
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious...
Critical
Unreviewed
CVE-2026-13768
was published
Jul 3, 2026
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Critical
CVE-2026-49352
was published
for
9router
(npm)
Jul 2, 2026
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded...
Critical
Unreviewed
CVE-2026-7839
was published
Jul 1, 2026
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ...
Critical
Unreviewed
CVE-2026-56278
was published
Jul 1, 2026
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services...
Critical
Unreviewed
CVE-2026-50110
was published
Jul 1, 2026
The DMP-5000 devices are shipped with a default administrative web account with weak...
Critical
Unreviewed
CVE-2026-31928
was published
Jun 27, 2026
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default...
Critical
Unreviewed
CVE-2026-56265
was published
Jun 21, 2026
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret...
Critical
Unreviewed
CVE-2025-10560
was published
Jun 18, 2026
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
Critical
CVE-2026-57147
was published
for
praisonai-platform
(pip)
Jun 18, 2026
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Critical
CVE-2026-57148
was published
for
praisonai-platform
(pip)
Jun 18, 2026
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Critical
CVE-2026-56266
was published
for
crawl4ai
(pip)
Jun 16, 2026
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...
Critical
Unreviewed
CVE-2026-50091
was published
Jun 12, 2026
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...
Critical
Unreviewed
CVE-2026-50083
was published
Jun 12, 2026
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are...
Critical
Unreviewed
CVE-2026-10557
was published
Jun 12, 2026
The
iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials...
Critical
Unreviewed
CVE-2026-11849
was published
Jun 12, 2026
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
Critical
CVE-2026-48031
was published
for
github.com/dhax/go-base
(Go)
Jun 10, 2026
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that...
Critical
Unreviewed
CVE-2025-71317
was published
Jun 5, 2026
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
Critical
CVE-2026-47410
was published
for
praisonai-platform
(pip)
May 29, 2026
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device...
Critical
Unreviewed
CVE-2026-7786
was published
May 29, 2026
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES...
Critical
Unreviewed
CVE-2026-49201
was published
May 29, 2026
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded...
Critical
Unreviewed
CVE-2026-24444
was published
May 28, 2026
ProTip!
Advisories are also available from the
GraphQL API