GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,608
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,528
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
272 advisories
Filter by severity
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable...
Moderate
Unreviewed
CVE-2026-71396
was published
Aug 28, 2026
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to...
Moderate
Unreviewed
CVE-2026-76131
was published
Aug 21, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk...
Moderate
Unreviewed
CVE-2026-76392
was published
Aug 20, 2026
A security vulnerability has been identified in the Planet9 desktop application where a hardcoded...
Moderate
Unreviewed
CVE-2026-50601
was published
Aug 17, 2026
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded...
Moderate
Unreviewed
CVE-2026-63702
was published
Aug 14, 2026
A hard-coded AWS IAM credentials vulnerability
in Koollab LMS allowed
an attacker to access...
Moderate
Unreviewed
CVE-2026-63239
was published
Jul 29, 2026
A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL...
Moderate
Unreviewed
CVE-2026-12001
was published
Jul 27, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential...
Moderate
Unreviewed
CVE-2025-59180
was published
Jul 27, 2026
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded...
Moderate
Unreviewed
CVE-2026-13728
was published
Jul 3, 2026
Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Moderate
Unreviewed
CVE-2026-9260
was published
Jun 16, 2026
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows...
Moderate
Unreviewed
CVE-2026-21404
was published
Jun 4, 2026
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking...
Moderate
Unreviewed
CVE-2026-49204
was published
Jun 4, 2026
Mercusys AC12G (EU) V1 with firmware AC12G(EU)_V1_200909 contains hardcoded WiFi driver...
Moderate
Unreviewed
CVE-2026-36616
was published
Jun 3, 2026
The PDBM application relies on a static, hard‑coded secret embedded
in the PDBM.exe executable....
Moderate
Unreviewed
CVE-2026-25600
was published
Jun 1, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in settings.inc.php that...
Moderate
Unreviewed
CVE-2026-48244
was published
May 21, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded Google Maps API key in tables.php that is...
Moderate
Unreviewed
CVE-2026-48245
was published
May 21, 2026
Open ISES Tickets before 3.44.2 embeds a hardcoded WhitePages reverse-phone API key in wp1.php...
Moderate
Unreviewed
CVE-2026-48243
was published
May 21, 2026
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker...
Moderate
Unreviewed
CVE-2026-8605
was published
May 19, 2026
ogham-mcp had credentials embedded in published PyPI sdists -- Neon postgres URLs and Voyage API key
Moderate
GHSA-8pqq-224h-x875
was published
for
ogham-mcp
(pip)
May 5, 2026
Flowise: Weak Default Token Hash Secret
Moderate
CVE-2026-56269
was published
for
flowise
(npm)
Apr 16, 2026
Flowise: Weak Default Express Session Secret
Moderate
GHSA-2qqc-p94c-hxwh
was published
for
flowise
(npm)
Apr 16, 2026
CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access...
Moderate
Unreviewed
CVE-2026-4832
was published
Apr 14, 2026
A vulnerability was identified in MEPIS RM, an industrial
software product developed by Metronik....
Moderate
Unreviewed
CVE-2026-25601
was published
Apr 1, 2026
AL-KO Robolinho Update Software has hard-coded AWS Access and Secret keys that allow anyone to...
Moderate
Unreviewed
CVE-2026-1612
was published
Mar 30, 2026
Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious...
Moderate
Unreviewed
CVE-2025-9497
was published
Mar 28, 2026
ProTip!
Advisories are also available from the
GraphQL API