GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
22
Go
2,095
Maven
5,000+
npm
3,760
NuGet
678
pip
3,446
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
435 advisories
Filter by severity
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5...
High
Unreviewed
CVE-2022-29060
was published
Jul 20, 2022
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This...
High
Unreviewed
CVE-2022-32389
was published
Jul 15, 2022
IBM QRadar Network Security 5.4.0 and 5.5.0 contains hard-coded credentials, such as a password...
High
Unreviewed
CVE-2020-4157
was published
Jul 13, 2022
Huawei OceanStor 5600 V3 V300R003C00 has a hardcoded SSH key vulnerability; the hardcoded keys...
High
Unreviewed
CVE-2016-8754
was published
May 17, 2022
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The...
High
Unreviewed
CVE-2016-8361
was published
May 17, 2022
A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa...
High
Unreviewed
CVE-2017-9132
was published
May 17, 2022
This vulnerability affects all of the company's products that also include the FW versions:...
High
Unreviewed
CVE-2022-30627
was published
Jul 19, 2022
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users...
High
Unreviewed
CVE-2017-5167
was published
May 17, 2022
Dell Enterprise SONiC OS, 4.0.0, 4.0.1, contain a cryptographic key vulnerability in SSH. An...
High
Unreviewed
CVE-2022-34425
was published
Oct 11, 2022
A vulnerability was found in GE Voluson S8. It has been rated as critical. This issue affects the...
High
Unreviewed
CVE-2020-36547
was published
Jun 18, 2022
Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller...
High
Unreviewed
CVE-2022-30997
was published
Jun 29, 2022
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a...
High
Unreviewed
CVE-2017-9488
was published
May 17, 2022
A vulnerability has been identified in Spectrum Power 4 (All versions using Shared HIS), Spectrum...
High
Unreviewed
CVE-2022-26476
was published
Jun 15, 2022
Multiple vulnerabilities in the web-based management interface of Cisco Business Process...
High
Unreviewed
CVE-2021-1574
was published
May 24, 2022
MapGIS IGServer 10.5.6.11 is vulnerable to Arbitrary file deletion.
High
Unreviewed
CVE-2022-36171
was published
Aug 20, 2022
Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded...
High
Unreviewed
CVE-2022-31460
was published
Jun 3, 2022
WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an...
High
Unreviewed
CVE-2017-2283
was published
May 17, 2022
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password ...
High
Unreviewed
CVE-2022-31462
was published
Jun 3, 2022
WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an...
High
Unreviewed
CVE-2017-2280
was published
May 17, 2022
The Java keystore in all versions and editions of Rapid7 Nexpose prior to 6.4.50 is encrypted...
High
Unreviewed
CVE-2017-5230
was published
May 17, 2022
The software contains a hard-coded password it uses for its own inbound authentication or for...
High
Unreviewed
CVE-2021-27438
was published
May 24, 2022
An issue was discovered in the IGEL Universal Management Suite (UMS) 6.07.100. A hardcoded DES...
High
Unreviewed
CVE-2022-25806
was published
Jun 10, 2022
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows...
High
Unreviewed
CVE-2020-7352
was published
May 24, 2022
An attacker can gain VxWorks Shell after login due to hard-coded credentials on a KUKA KR C4...
High
Unreviewed
CVE-2021-33014
was published
May 27, 2022
An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam...
High
Unreviewed
CVE-2018-4017
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API