GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,714
Erlang
34
GitHub Actions
28
Go
2,301
Maven
5,000+
npm
3,942
NuGet
711
pip
3,711
Pub
12
RubyGems
920
Rust
960
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,260 advisories
Filter by severity
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This...
Moderate
Unreviewed
CVE-2025-41380
was published
May 23, 2025
There are several scripts in the web interface that are accessible via undocumented hard-coded...
Moderate
Unreviewed
CVE-2025-48414
was published
May 21, 2025
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating...
High
Unreviewed
CVE-2025-48413
was published
May 21, 2025
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to...
Moderate
Unreviewed
CVE-2025-4876
was published
May 19, 2025
In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the...
Critical
Unreviewed
CVE-2025-45746
was published
May 13, 2025
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-27488
was published
May 13, 2025
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an...
Moderate
Unreviewed
CVE-2025-47730
was published
May 8, 2025
A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE...
Critical
Unreviewed
CVE-2025-20188
was published
May 7, 2025
In Optigo Networks ONS NC600 versions 4.2.1-084 through 4.7.2-330, an attacker could connect with...
Critical
Unreviewed
CVE-2025-4041
was published
May 6, 2025
An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The...
High
Unreviewed
CVE-2025-32888
was published
May 2, 2025
An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The...
High
Unreviewed
CVE-2025-32889
was published
May 2, 2025
CWE-798: Use of Hard-coded Credentials
Moderate
Unreviewed
CVE-2025-23179
was published
Apr 29, 2025
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in...
Moderate
Unreviewed
CVE-2024-13688
was published
Apr 28, 2025
NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR...
Critical
Unreviewed
CVE-2025-32985
was published
Apr 25, 2025
Quantum StorNext Web GUI API before 7.2.4 grants access to internal StorNext configuration and...
High
Unreviewed
CVE-2025-46617
was published
Apr 25, 2025
UNI-NMS-Lite uses hard-coded credentials that could allow an
unauthenticated attacker to read,...
Critical
Unreviewed
CVE-2025-46274
was published
Apr 25, 2025
UNI-NMS-Lite uses hard-coded credentials that could allow an
unauthenticated attacker to gain...
Critical
Unreviewed
CVE-2025-46273
was published
Apr 25, 2025
CarlinKit CPC200-CCPA Wireless Hotspot Hard-Coded Credentials Authentication Bypass Vulnerability...
High
Unreviewed
CVE-2025-2765
was published
Apr 23, 2025
Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access...
Critical
Unreviewed
CVE-2025-28230
was published
Apr 21, 2025
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected...
Critical
Unreviewed
CVE-2024-41794
was published
Apr 8, 2025
We observed that Intellispace Portal binaries doesn’t have any protection mechanisms to prevent...
High
Unreviewed
CVE-2025-3426
was published
Apr 7, 2025
Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization...
Critical
Unreviewed
CVE-2025-30406
was published
Apr 3, 2025
An issue was discovered on the Audi Universal Traffic Recorder 2.88. It has Susceptibility to...
High
Unreviewed
CVE-2025-30118
was published
Mar 25, 2025
A specific type of ArcGIS Enterprise deployment, is vulnerable to a Password Recovery...
Critical
Unreviewed
CVE-2025-2538
was published
Mar 20, 2025
An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for...
Critical
Unreviewed
CVE-2025-30137
was published
Mar 18, 2025
ProTip!
Advisories are also available from the
GraphQL API