GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,586 advisories
Filter by severity
The vulnerability allows the unauthorised generation of physical access QR codes due to the use...
High
Unreviewed
CVE-2026-12587
was published
Aug 28, 2026
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded...
High
Unreviewed
CVE-2026-19412
was published
Aug 28, 2026
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable...
Moderate
Unreviewed
CVE-2026-71396
was published
Aug 28, 2026
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models...
Critical
Unreviewed
CVE-2026-78251
was published
Aug 27, 2026
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
Critical
Unreviewed
CVE-2026-75896
was published
Aug 26, 2026
FA-50 all versions contain hard-coded credentials.
An attacker, who knows the credentials and has...
High
Unreviewed
CVE-2026-59769
was published
Aug 25, 2026
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to...
Moderate
Unreviewed
CVE-2026-76131
was published
Aug 21, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk...
Moderate
Unreviewed
CVE-2026-76392
was published
Aug 20, 2026
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret...
Critical
Unreviewed
CVE-2026-71960
was published
Aug 19, 2026
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector...
Critical
Unreviewed
CVE-2021-43717
was published
Aug 18, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py...
High
Unreviewed
CVE-2026-74893
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone...
High
Unreviewed
CVE-2026-74892
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server...
High
Unreviewed
CVE-2026-74891
was published
Aug 17, 2026
A security vulnerability has been identified in the Planet9 desktop application where a hardcoded...
Moderate
Unreviewed
CVE-2026-50601
was published
Aug 17, 2026
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded...
Moderate
Unreviewed
CVE-2026-63702
was published
Aug 14, 2026
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before...
Critical
Unreviewed
CVE-2026-19871
was published
Aug 14, 2026
An undocumented hard-coded credential, shared by all device units, is authorized to bypass...
High
Unreviewed
CVE-2026-18164
was published
Aug 13, 2026
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded...
High
Unreviewed
CVE-2026-13460
was published
Aug 13, 2026
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI...
Critical
Unreviewed
CVE-2026-67614
was published
Aug 13, 2026
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an...
Critical
Unreviewed
CVE-2026-59507
was published
Aug 13, 2026
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every...
Critical
Unreviewed
CVE-2026-73519
was published
Aug 13, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue...
High
Unreviewed
CVE-2026-14866
was published
Aug 12, 2026
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive...
Critical
Unreviewed
CVE-2026-67568
was published
Aug 12, 2026
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in...
Critical
Unreviewed
CVE-2026-69102
was published
Aug 11, 2026
SAP Advanced Planning and Optimization (Model Mix Planning) contains a hardcoded credential...
Low
Unreviewed
CVE-2026-58245
was published
Aug 11, 2026
ProTip!
Advisories are also available from the
GraphQL API