GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,167 advisories
Filter by severity
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in...
Moderate
Unreviewed
CVE-2024-5764
was published
Oct 23, 2024
A vulnerability, which was classified as problematic, has been found in Cosmote Greece What's Up...
Low
Unreviewed
CVE-2024-10748
was published
Nov 4, 2024
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily...
Critical
Unreviewed
CVE-2024-51431
was published
Nov 1, 2024
A vulnerability in Cisco Firepower Threat Defense (FTD) Software for Cisco Firepower 1000, 2100,...
Critical
Unreviewed
CVE-2024-20412
was published
Oct 23, 2024
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between...
Moderate
Unreviewed
CVE-2024-45165
was published
Aug 22, 2024
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with...
Moderate
Unreviewed
CVE-2024-20280
was published
Oct 16, 2024
An issue in Automatic Systems SOC FL9600 FastLine v.lego_T04E00 allows a remote attacker to...
High
Unreviewed
CVE-2023-37608
was published
Jan 3, 2024
A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key,...
Low
Unreviewed
CVE-2023-20512
was published
Aug 13, 2024
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows...
High
Unreviewed
CVE-2024-28875
was published
Oct 30, 2024
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows...
High
Unreviewed
CVE-2024-31151
was published
Oct 30, 2024
IBM Flexible Service Processor (FSP) FW860.00 through FW860.B3, FW950.00 through FW950.C0, FW1030...
Critical
Unreviewed
CVE-2024-45656
was published
Oct 29, 2024
** UNSUPPORTED WHEN ASSIGNED ** D-Link DIR-890L 1.20b01 allows attackers to execute arbitrary...
High
Unreviewed
CVE-2022-29778
was published
Jun 4, 2022
A vulnerability has been identified in MXsecurity versions prior to v1.0.1. The vulnerability may...
Moderate
Unreviewed
CVE-2023-39982
was published
Sep 2, 2023
Neye3C v4.5.2.0 was discovered to contain a hardcoded encryption key in the firmware update...
Critical
Unreviewed
CVE-2024-48539
was published
Oct 24, 2024
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated...
Critical
Unreviewed
CVE-2023-47213
was published
Nov 16, 2023
MXsecurity software versions v1.1.0 and prior are vulnerable because of the use of hard-coded...
Moderate
Unreviewed
CVE-2024-4740
was published
Oct 18, 2024
Tenda G3 v15.01.0.5(2848_755)_EN was discovered to contain a hardcoded password vulnerability in ...
High
Unreviewed
CVE-2024-48192
was published
Oct 17, 2024
A vulnerability in the .sdd file allows an attacker to read default passwords stored in plain...
Critical
Unreviewed
CVE-2024-10025
was published
Oct 17, 2024
The devices contain two hard coded user accounts with hardcoded passwords that allow an...
Critical
Unreviewed
CVE-2024-45275
was published
Oct 15, 2024
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
Kaifa Technology WebITR is an online attendance system, it has a vulnerability in using hard...
Critical
Unreviewed
CVE-2023-48392
was published
Dec 15, 2023
Galaxy Software Services Vitals ESP is vulnerable to using a hard-coded encryption key. An...
Critical
Unreviewed
CVE-2023-37291
was published
Jul 21, 2023
It is possible to download the configuration backup without authorization and decrypt included...
High
Unreviewed
CVE-2023-49256
was published
Jan 12, 2024
An attacker can access the maintenance console using hard coded credentials for a hidden wireless...
High
Unreviewed
CVE-2024-38281
was published
Jun 13, 2024
ProTip!
Advisories are also available from the
GraphQL API