GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,587 advisories
Filter by severity
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups...
High
Unreviewed
CVE-2026-36606
was published
Jun 3, 2026
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard...
High
Unreviewed
CVE-2019-25722
was published
Jun 2, 2026
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server...
High
Unreviewed
CVE-2026-42251
was published
Jun 1, 2026
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable....
Moderate
Unreviewed
CVE-2026-25600
was published
Jun 1, 2026
Apache Solr has hardcoded credentials in the Basic Authentication setup tool
High
CVE-2026-44825
was published
for
org.apache.solr:solr-core
(Maven)
Jun 1, 2026
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
Critical
CVE-2026-47410
was published
for
praisonai-platform
(pip)
May 29, 2026
Danelec MacGregor Voyage Data Recorder
includes default accounts with hard-coded credentials.
High
Unreviewed
CVE-2026-42929
was published
May 29, 2026
AgenticMail API/storage and outbound relay hardening fixes
High
CVE-2026-47255
was published
for
@agenticmail/api
(npm)
May 29, 2026
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
device...
Critical
Unreviewed
CVE-2026-7786
was published
May 29, 2026
The upload.cgi binary, responsible for processing device backups, contains a hardcoded AES...
Critical
Unreviewed
CVE-2026-49201
was published
May 29, 2026
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded...
Critical
Unreviewed
CVE-2026-24444
was published
May 28, 2026
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a...
High
Unreviewed
CVE-2026-5065
was published
May 27, 2026
Netis AC1200 Router NC21 V4.0.1.4296 contains a hard-coded root credential stored in /etc/shadow...
High
Unreviewed
CVE-2026-36538
was published
May 27, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that...
Moderate
Unreviewed
CVE-2026-48244
was published
May 21, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is...
Moderate
Unreviewed
CVE-2026-48245
was published
May 21, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php...
Moderate
Unreviewed
CVE-2026-48243
was published
May 21, 2026
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database connection credentials (host,...
Critical
Unreviewed
CVE-2026-48242
was published
May 21, 2026
Open ISES Tickets before 3.44.2 contains hardcoded MySQL database credentials in loader.php (a...
Critical
Unreviewed
CVE-2026-48241
was published
May 21, 2026
Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential...
Critical
Unreviewed
CVE-2026-9139
was published
May 20, 2026
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker...
Moderate
Unreviewed
CVE-2026-8605
was published
May 19, 2026
Comarch ERP Optima client makes use of a hard-coded password for a database user. These...
High
Unreviewed
CVE-2025-68421
was published
May 14, 2026
Huawei HG630 V2 router contains an authentication bypass vulnerability that allows...
High
Unreviewed
CVE-2020-37220
was published
May 13, 2026
A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter...
High
Unreviewed
CVE-2026-33893
was published
May 12, 2026
Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0,...
Critical
Unreviewed
CVE-2026-40636
was published
May 11, 2026
Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware...
Critical
Unreviewed
CVE-2026-7414
was published
May 7, 2026
ProTip!
Advisories are also available from the
GraphQL API