GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
430 advisories
Filter by severity
The Android Client application, when enrolled to the AppHub server, connects to an MQTT
broker to...
High
Unreviewed
CVE-2023-46102
was published
Oct 25, 2023
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify...
High
Unreviewed
CVE-2023-41372
was published
Oct 25, 2023
The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk...
High
Unreviewed
CVE-2023-26219
was published
Oct 25, 2023
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
High
Unreviewed
CVE-2023-41713
was published
Oct 18, 2023
The BIG-IP SPK TMM (Traffic Management Module) f5-debug-sidecar and f5-debug-sshd containers...
High
Unreviewed
CVE-2023-45226
was published
Oct 10, 2023
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05.11 (only...
High
Unreviewed
CVE-2023-36380
was published
Oct 10, 2023
All versions of NetMan 204 allow an attacker that knows the MAC and serial number of the device...
High
Unreviewed
CVE-2022-47891
was published
Oct 3, 2023
Vulnerability in the Elasticsearch database used in the of Cisco SD-WAN vManage software could...
High
Unreviewed
CVE-2023-20034
was published
Sep 27, 2023
Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key...
High
Unreviewed
CVE-2023-43637
was published
Sep 21, 2023
Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One...
High
Unreviewed
CVE-2023-31808
was published
Sep 19, 2023
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain...
High
Unreviewed
CVE-2023-42328
was published
Sep 18, 2023
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
High
Unreviewed
CVE-2023-41595
was published
Sep 18, 2023
A use of hard-coded credentials vulnerability [CWE-798] in FortiTester 2.3.0 through 7.2.3 may...
High
Unreviewed
CVE-2023-40717
was published
Sep 13, 2023
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of...
High
Unreviewed
CVE-2023-39421
was published
Sep 7, 2023
The RDPCore.dll component as used in the IRM Next Generation booking engine, allows a remote user...
High
Unreviewed
CVE-2023-39420
was published
Sep 7, 2023
Archer C50 firmware versions prior to 'Archer C50(JP)_V3_230505' and Archer C55 firmware versions...
High
Unreviewed
CVE-2023-32619
was published
Sep 6, 2023
Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL...
High
Unreviewed
CVE-2023-31173
was published
Aug 31, 2023
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man...
High
Unreviewed
CVE-2023-23771
was published
Aug 29, 2023
Netmaker has Hardcoded DNS Secret Key
High
CVE-2023-32077
was published
for
github.com/gravitl/netmaker
(Go)
Aug 25, 2023
The LMS5xx uses hard-coded credentials, which potentially allow low-skilled
unauthorized remote...
High
Unreviewed
CVE-2023-4419
was published
Aug 24, 2023
EdgeConnect SD-WAN Orchestrator instances prior to the versions resolved in this advisory were...
High
Unreviewed
CVE-2023-37426
was published
Aug 22, 2023
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due...
High
Unreviewed
CVE-2023-22957
was published
Aug 11, 2023
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a...
High
Unreviewed
CVE-2023-22956
was published
Aug 11, 2023
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated,...
High
Unreviewed
CVE-2023-37857
was published
Aug 9, 2023
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on...
High
Unreviewed
CVE-2023-21652
was published
Aug 8, 2023
ProTip!
Advisories are also available from the
GraphQL API