GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,409
Erlang
33
GitHub Actions
22
Go
2,146
Maven
5,000+
npm
3,808
NuGet
687
pip
3,481
Pub
12
RubyGems
897
Rust
899
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,212 advisories
Filter by severity
Several versions of
ALEOS, including ALEOS 4.16.0, use a hardcoded
SSL certificate...
High
Unreviewed
CVE-2023-40464
was published
Dec 5, 2023
The password for access to the debugging console of the PoWer Controller chip (PWC) of the MIB3...
Low
Unreviewed
CVE-2023-28895
was published
Dec 1, 2023
Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain hardcoded credentials...
Critical
Unreviewed
CVE-2023-23324
was published
Nov 29, 2023
The FACSChorus software contains sensitive information stored in plaintext. A threat actor could...
Moderate
Unreviewed
CVE-2023-29064
was published
Nov 28, 2023
Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to a hard-coded JWT...
High
Unreviewed
CVE-2023-47315
was published
Nov 22, 2023
Archery v1.10.0 uses a non-random or static IV for Cipher Block Chaining (CBC) mode in AES...
High
Unreviewed
CVE-2023-48053
was published
Nov 16, 2023
SuperAGI v0.0.13 was discovered to use a hardcoded key for encryption operations. This...
High
Unreviewed
CVE-2023-48055
was published
Nov 16, 2023
First Corporation's DVRs use a hard-coded password, which may allow a remote unauthenticated...
Critical
Unreviewed
CVE-2023-47213
was published
Nov 16, 2023
Dell ELab-Navigator, version 3.1.9 contains a hard-coded credential vulnerability. A local...
High
Unreviewed
CVE-2023-44296
was published
Nov 16, 2023
A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 -...
Moderate
Unreviewed
CVE-2023-40719
was published
Nov 14, 2023
A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7...
Moderate
Unreviewed
CVE-2023-33304
was published
Nov 14, 2023
Natus NeuroWorks and SleepWorks before 8.4 GMA3 utilize a default password of xltek for the...
Critical
Unreviewed
CVE-2023-47800
was published
Nov 10, 2023
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be...
High
Unreviewed
CVE-2023-41137
was published
Nov 9, 2023
Weintek EasyBuilder Pro contains a vulnerability that, even when the private key is...
Critical
Unreviewed
CVE-2023-5777
was published
Nov 6, 2023
Dromara Lamp-Cloud Use of Hard-coded Cryptographic Key
High
CVE-2023-31579
was published
for
top.tangyh.basic:lamp-core
(Maven)
Nov 3, 2023
VinChin Backup & Recovery v5.0.*, v6.0.*, v6.7.*, and v7.0.* was discovered to contain hardcoded...
Critical
Unreviewed
CVE-2023-45499
was published
Oct 27, 2023
Hardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/...
Critical
Unreviewed
CVE-2018-17558
was published
Oct 27, 2023
The Android Client application, when enrolled to the AppHub server, connects to an MQTT
broker to...
High
Unreviewed
CVE-2023-46102
was published
Oct 25, 2023
The vulnerability allows an unprivileged (untrusted) third- party application to arbitrary modify...
High
Unreviewed
CVE-2023-41372
was published
Oct 25, 2023
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
Critical
Unreviewed
CVE-2023-42492
was published
Oct 25, 2023
Sureness uses hardcoded key
Critical
CVE-2023-31581
was published
for
com.usthe.sureness:sureness-core
(Maven)
Oct 25, 2023
The Hawk Console and Hawk Agent components of TIBCO Software Inc.'s TIBCO Hawk, TIBCO Hawk...
High
Unreviewed
CVE-2023-26219
was published
Oct 25, 2023
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or...
Critical
Unreviewed
CVE-2022-22466
was published
Oct 23, 2023
SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function.
High
Unreviewed
CVE-2023-41713
was published
Oct 18, 2023
IBM Security Verify Governance 10.0 contains hard-coded credentials, such as a password or...
Critical
Unreviewed
CVE-2023-33836
was published
Oct 16, 2023
ProTip!
Advisories are also available from the
GraphQL API