GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,724
Maven
5,000+
npm
5,000+
NuGet
1,116
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,568
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,606 advisories
Filter by severity
DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component....
Moderate
Unreviewed
CVE-2026-17038
was published
Sep 10, 2026
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This...
High
Unreviewed
CVE-2026-81640
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79738
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79740
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79950
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-79731
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80170
was published
Sep 7, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-80134
was published
Sep 7, 2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded...
High
Unreviewed
CVE-2026-77847
was published
Sep 4, 2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a...
Moderate
Unreviewed
CVE-2026-5522
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85148
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Moderate
Unreviewed
CVE-2026-85149
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85146
was published
Sep 4, 2026
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the...
High
Unreviewed
CVE-2026-85451
was published
Sep 4, 2026
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that...
Critical
Unreviewed
CVE-2026-85391
was published
Sep 3, 2026
A data exposure vulnerability exists in the affected product. There are hardcoded links in the...
High
Unreviewed
CVE-2024-7952
was published
Sep 1, 2026
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft...
Critical
Unreviewed
CVE-2026-18931
was published
Sep 1, 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers...
Critical
Unreviewed
CVE-2026-38577
was published
Aug 31, 2026
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that...
Critical
Unreviewed
CVE-2026-82448
was published
Aug 29, 2026
The vulnerability allows the unauthorised generation of physical access QR codes due to the use...
High
Unreviewed
CVE-2026-12587
was published
Aug 28, 2026
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded...
High
Unreviewed
CVE-2026-19412
was published
Aug 28, 2026
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable...
Moderate
Unreviewed
CVE-2026-71396
was published
Aug 28, 2026
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to...
High
Unreviewed
CVE-2026-37012
was published
Aug 27, 2026
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models...
Critical
Unreviewed
CVE-2026-78251
was published
Aug 27, 2026
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
Critical
Unreviewed
CVE-2026-75896
was published
Aug 26, 2026
ProTip!
Advisories are also available from the
GraphQL API