GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,587 advisories
Filter by severity
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Critical
CVE-2026-49352
was published
for
9router
(npm)
Jul 2, 2026
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded...
Critical
Unreviewed
CVE-2026-7839
was published
Jul 1, 2026
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ...
Critical
Unreviewed
CVE-2026-56278
was published
Jul 1, 2026
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services...
Critical
Unreviewed
CVE-2026-50110
was published
Jul 1, 2026
The DMP-5000 devices are shipped with a default administrative web account with weak...
Critical
Unreviewed
CVE-2026-31928
was published
Jun 27, 2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8...
High
Unreviewed
CVE-2026-12628
was published
Jun 22, 2026
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default...
Critical
Unreviewed
CVE-2026-56265
was published
Jun 21, 2026
Worksnaps before version 1.6.20260201 contains hardcoded cloud credentials and related secret...
Critical
Unreviewed
CVE-2025-10560
was published
Jun 18, 2026
praisonai-platform: default JWT signing secret 'dev-secret-change-me' enables token forgery
Critical
CVE-2026-57147
was published
for
praisonai-platform
(pip)
Jun 18, 2026
praisonai-platform 0.1.4 still boots on the hardcoded JWT secret dev-secret-change-me (default-open production guard)
Critical
CVE-2026-57148
was published
for
praisonai-platform
(pip)
Jun 18, 2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for...
High
Unreviewed
CVE-2026-5667
was published
Jun 17, 2026
The device has a webserver that exposes a REST API authenticated with a constant token. The...
High
Unreviewed
CVE-2026-22312
was published
Jun 16, 2026
Crawl4AI: Multiple Docker API Vulnerabilities - File Write, SSRF, Auth Bypass, XSS, JS Execution
Critical
CVE-2026-56266
was published
for
crawl4ai
(pip)
Jun 16, 2026
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Moderate
Unreviewed
CVE-2026-9260
was published
Jun 16, 2026
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...
Critical
Unreviewed
CVE-2026-50091
was published
Jun 12, 2026
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which...
Critical
Unreviewed
CVE-2026-50083
was published
Jun 12, 2026
The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are...
Critical
Unreviewed
CVE-2026-10557
was published
Jun 12, 2026
The
iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials...
Critical
Unreviewed
CVE-2026-11849
was published
Jun 12, 2026
Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery
Critical
CVE-2026-48031
was published
for
github.com/dhax/go-base
(Go)
Jun 10, 2026
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that...
Critical
Unreviewed
CVE-2025-71317
was published
Jun 5, 2026
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows...
Moderate
Unreviewed
CVE-2026-21404
was published
Jun 4, 2026
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets,...
High
Unreviewed
CVE-2026-50213
was published
Jun 4, 2026
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking...
Moderate
Unreviewed
CVE-2026-49204
was published
Jun 4, 2026
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in...
High
Unreviewed
CVE-2026-8876
was published
Jun 3, 2026
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver...
Moderate
Unreviewed
CVE-2026-36616
was published
Jun 3, 2026
ProTip!
Advisories are also available from the
GraphQL API