GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,169 advisories
Filter by severity
A vulnerability was found in Telecommunication Software SAMwin Contact Center Suite 5.1. It has...
Critical
Unreviewed
CVE-2013-10002
was published
May 25, 2022
An attacker can gain full access (read/write/delete) to sensitive folders due to hard-coded...
Critical
Unreviewed
CVE-2021-33016
was published
May 27, 2022
An issue was discovered in Hyland OnBase through 18.0.0.32 and 19.x through 19.8.9.1000. PKI...
Moderate
Unreviewed
CVE-2020-25256
was published
May 24, 2022
An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4...
High
Unreviewed
CVE-2021-33014
was published
May 27, 2022
SOPlanning before 1.47 has Incorrect Access Control because certain secret key information, and...
Critical
Unreviewed
CVE-2020-13963
was published
May 24, 2022
Undocumented Default Cryptographic Key Vulnerability in Cohesity DataPlatform version 6.3 prior 6...
Critical
Unreviewed
CVE-2021-28123
was published
May 24, 2022
Sanitization Management System v1.0 was discovered to contain hardcoded credentials which allows...
Critical
Unreviewed
CVE-2022-44096
was published
Nov 30, 2022
An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam...
High
Unreviewed
CVE-2018-4017
was published
May 24, 2022
Versions of the Official Alpine Linux Docker images (since v3.3) contain a NULL password for the ...
Critical
Unreviewed
CVE-2019-5021
was published
May 24, 2022
IBM QRadar 7.3.0 to 7.3.3 Patch 2 contains hard-coded credentials, such as a password or...
Moderate
Unreviewed
CVE-2020-4269
was published
May 24, 2022
IBM Spectrum Protect Plus 10.1.0 thorugh 10.1.6 contains hard-coded credentials, such as a...
Critical
Unreviewed
CVE-2020-4854
was published
May 24, 2022
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows...
Critical
Unreviewed
CVE-2022-44097
was published
Nov 30, 2022
A specific file on the sERP server if Kyungrinara(ERP solution) has a fixed password with the...
Critical
Unreviewed
CVE-2022-41157
was published
Nov 25, 2022
An exploitable unsafe default configuration vulnerability exists in the TURN server function of...
Critical
Unreviewed
CVE-2018-4059
was published
May 13, 2022
Use of hard-coded TLS certificate by default allows an attacker to perform Man-in-the-Middle ...
High
Unreviewed
CVE-2021-4228
was published
Oct 24, 2022
ASUS WebStorage has a hardcoded API Token in the APP source code. An unauthenticated remote...
High
Unreviewed
CVE-2022-26672
was published
Apr 23, 2022
A vulnerability in the key-based SSH authentication mechanism of Cisco Umbrella Virtual Appliance...
High
Unreviewed
CVE-2022-20773
was published
Apr 22, 2022
An authentication bypass vulnerability exists in the device password generation functionality of...
Critical
Unreviewed
CVE-2021-40422
was published
Apr 15, 2022
Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the...
Low
Unreviewed
CVE-2020-25168
was published
Apr 15, 2022
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView...
Critical
Unreviewed
CVE-2021-40390
was published
Apr 15, 2022
Hard-coded credentials allow administrators to access the shell via the SD-WAN CLI
Moderate
Unreviewed
CVE-2022-27506
was published
Apr 14, 2022
Dell EMC PowerScale OneFS 8.1.x - 9.1.x contain hard coded credentials. This allows a local user...
Moderate
Unreviewed
CVE-2022-22560
was published
Apr 13, 2022
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1,...
Critical
Unreviewed
CVE-2022-23441
was published
Apr 7, 2022
Taiwan Secom Dr.ID Access Control system’s login page has a hard-coded credential in the source...
High
Unreviewed
CVE-2022-26671
was published
Apr 8, 2022
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across...
Critical
Unreviewed
CVE-2022-25569
was published
Apr 5, 2022
ProTip!
Advisories are also available from the
GraphQL API