GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
1,179 advisories
Filter by severity
Acclaim USAHERDS through 7.4.0.1 uses hard-coded credentials.
High
Unreviewed
CVE-2021-44207
was published
Dec 22, 2021
Use of a hard-coded password for a database administrator account created during Wapro ERP...
Critical
Unreviewed
CVE-2024-4996
was published
Dec 18, 2024
ui/pref/ProxyPrefView.java in weasis-core in Weasis 4.5.1 has a hardcoded key for symmetric...
Critical
Unreviewed
CVE-2024-55557
was published
Dec 16, 2024
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of...
Moderate
Unreviewed
CVE-2023-30904
was published
Jun 16, 2023
The application uses several hard-coded credentials to encrypt config files during backup, to...
High
Unreviewed
CVE-2024-28146
was published
Dec 12, 2024
Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc...
High
Unreviewed
CVE-2024-54749
was published
Dec 6, 2024
Snap One OvrC Pro versions prior to 7.2 have their own locally...
Critical
Unreviewed
CVE-2023-31240
was published
May 22, 2023
Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow...
Critical
Unreviewed
CVE-2024-54750
was published
Dec 6, 2024
A vulnerability in the SonicWall SMA100 SSLVPN
firmware 10.2.1.13-72sv and earlier versions...
Moderate
Unreviewed
CVE-2024-45319
was published
Dec 5, 2024
A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive...
Moderate
Unreviewed
CVE-2024-53614
was published
Dec 4, 2024
Ever Traduora 0.20.0 and below is vulnerable to Privilege Escalation due to the use of a hard...
Critical
Unreviewed
CVE-2024-53484
was published
Dec 2, 2024
IBM Cognos Controller 11.0.0 and 11.0.1
contains hard-coded credentials, such as a...
High
Unreviewed
CVE-2024-41777
was published
Dec 3, 2024
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials,...
Critical
Unreviewed
CVE-2024-49805
was published
Nov 29, 2024
IBM Security Verify Access Appliance 10.0.0 through 10.0.8
contains hard-coded credentials,...
Critical
Unreviewed
CVE-2024-49806
was published
Nov 29, 2024
The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability,...
Critical
Unreviewed
CVE-2024-28987
was published
Aug 22, 2024
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower...
High
Unreviewed
CVE-2020-3318
was published
May 24, 2022
Multiple vulnerabilities in Cisco Firepower Management Center (FMC) Software and Cisco Firepower...
Low
Unreviewed
CVE-2020-3301
was published
May 24, 2022
Keycloak Build Process Exposes Sensitive Data
High
CVE-2024-10451
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
Hard coded credentials in FreeTAKServer
High
CVE-2022-25510
was published
for
FreeTAKServer
(pip)
Mar 12, 2022
There are several hidden accounts. Some of them are intended for maintenance engineers, and with...
Critical
Unreviewed
CVE-2024-35244
was published
Nov 26, 2024
API keys for some cloud services are hardcoded in the "main" binary. As for the details of...
Critical
Unreviewed
CVE-2024-36248
was published
Nov 26, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded...
Moderate
Unreviewed
CVE-2024-40410
was published
Nov 14, 2024
Duplicate Advisory: Keycloak Build Process Exposes Sensitive Data
Moderate
GHSA-jcgg-mg9g-p9wf
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
•
withdrawn
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2023-51629
was published
May 3, 2024
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated...
Moderate
Unreviewed
CVE-2024-11026
was published
Nov 9, 2024
ProTip!
Advisories are also available from the
GraphQL API