GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
572 advisories
Filter by severity
The vulnerability allows the unauthorised generation of physical access QR codes due to the use...
High
Unreviewed
CVE-2026-12587
was published
Aug 28, 2026
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded...
High
Unreviewed
CVE-2026-19412
was published
Aug 28, 2026
FA-50 all versions contain hard-coded credentials.
An attacker, who knows the credentials and has...
High
Unreviewed
CVE-2026-59769
was published
Aug 25, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py...
High
Unreviewed
CVE-2026-74893
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone...
High
Unreviewed
CVE-2026-74892
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server...
High
Unreviewed
CVE-2026-74891
was published
Aug 17, 2026
An undocumented hard-coded credential, shared by all device units, is authorized to bypass...
High
Unreviewed
CVE-2026-18164
was published
Aug 13, 2026
IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded...
High
Unreviewed
CVE-2026-13460
was published
Aug 13, 2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue...
High
Unreviewed
CVE-2026-14866
was published
Aug 12, 2026
Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive...
High
Unreviewed
CVE-2026-6374
was published
Aug 10, 2026
By accessing unencrypted information in the device firmware, an attacker can obtain the initial...
High
Unreviewed
CVE-2026-49007
was published
Aug 7, 2026
Affected
Omada devices rely on embedded certificates that are shared across deployments
to...
High
Unreviewed
CVE-2025-15628
was published
Aug 3, 2026
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering...
High
Unreviewed
CVE-2026-65313
was published
Jul 31, 2026
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to...
High
Unreviewed
CVE-2026-13463
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs...
High
Unreviewed
CVE-2021-32085
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs...
High
Unreviewed
CVE-2021-32087
was published
Jul 28, 2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8...
High
Unreviewed
CVE-2026-12628
was published
Jun 22, 2026
Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for...
High
Unreviewed
CVE-2026-5667
was published
Jun 17, 2026
The device has a webserver that exposes a REST API authenticated with a constant token. The...
High
Unreviewed
CVE-2026-22312
was published
Jun 16, 2026
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets,...
High
Unreviewed
CVE-2026-50213
was published
Jun 4, 2026
Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in...
High
Unreviewed
CVE-2026-8876
was published
Jun 3, 2026
Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 encrypts configuration backups...
High
Unreviewed
CVE-2026-36606
was published
Jun 3, 2026
Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard...
High
Unreviewed
CVE-2019-25722
was published
Jun 2, 2026
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server...
High
Unreviewed
CVE-2026-42251
was published
Jun 1, 2026
Apache Solr has hardcoded credentials in the Basic Authentication setup tool
High
CVE-2026-44825
was published
for
org.apache.solr:solr-core
(Maven)
Jun 1, 2026
ProTip!
Advisories are also available from the
GraphQL API