GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
206 advisories
Filter by severity
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
Moderate
Unreviewed
CVE-2023-41611
was published
Sep 18, 2024
An information disclosure vulnerability in Totolink A830R V4.1.2cu.5182 allows attackers to...
Moderate
Unreviewed
CVE-2022-48067
was published
Jan 27, 2023
In the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The...
Moderate
Unreviewed
CVE-2025-30109
was published
Mar 18, 2025
Apache Submarine Commons Utils has a hard-coded secret
Moderate
CVE-2024-36264
was published
for
apache-submarine
(Maven)
Jun 12, 2024
IXON B.V. IXrouter IX2400 (Industrial Edge Gateway) v3.0 was discovered to contain hardcoded root...
Moderate
Unreviewed
CVE-2024-57790
was published
Feb 14, 2025
Hard-coded Credentials in CoolKit eWeLlink app are before 5.4.x on Android and IOS allows local...
Moderate
Unreviewed
CVE-2024-3130
was published
Apr 1, 2024
SolarWinds Web Help Desk was found to have a hardcoded cryptographic key that could allow the...
Moderate
Unreviewed
CVE-2024-28989
was published
Feb 11, 2025
ONTAP Select Deploy administration utility versions 9.12.1.x,
9.13.1.x and 9.14.1.x contain hard...
Moderate
Unreviewed
CVE-2024-21990
was published
Apr 17, 2024
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains a hardcoded password that can be...
Moderate
Unreviewed
CVE-2024-50690
was published
Jan 25, 2025
SunGrow WiNet-SV200.001.00.P027 and earlier versions contains hardcoded MQTT credentials that...
Moderate
Unreviewed
CVE-2024-50692
was published
Jan 25, 2025
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded...
Moderate
Unreviewed
CVE-2020-8657
was published
May 24, 2022
Dell RecoverPoint for Virtual Machines 6.0.x contains use of hard-coded credentials vulnerability...
Moderate
Unreviewed
CVE-2024-48007
was published
Dec 13, 2024
Flawed token generation implementation & Hard-coded key implementation
Moderate
Unreviewed
CVE-2024-55927
was published
Jan 23, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 and IBM Controller 11.1.0 is vulnerable to exposure...
Moderate
Unreviewed
CVE-2024-28778
was published
Jan 7, 2025
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of...
Moderate
Unreviewed
CVE-2023-30904
was published
Jun 16, 2023
A vulnerability in the SonicWall SMA100 SSLVPN
firmware 10.2.1.13-72sv and earlier versions...
Moderate
Unreviewed
CVE-2024-45319
was published
Dec 5, 2024
A hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive...
Moderate
Unreviewed
CVE-2024-53614
was published
Dec 4, 2024
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded...
Moderate
Unreviewed
CVE-2024-40410
was published
Nov 14, 2024
Duplicate Advisory: Keycloak Build Process Exposes Sensitive Data
Moderate
GHSA-jcgg-mg9g-p9wf
was published
for
org.keycloak:keycloak-quarkus-server
(Maven)
Nov 25, 2024
•
withdrawn
D-Link DCS-8300LHV2 ONVIF Hardcoded PIN Authentication Bypass Vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2023-51629
was published
May 3, 2024
A vulnerability was found in Intelligent Apps Freenow App 12.10.0 on Android. It has been rated...
Moderate
Unreviewed
CVE-2024-11026
was published
Nov 9, 2024
"Piccoma" App for Android and iOS versions prior to 6.20.0 uses a hard-coded API key for an...
Moderate
Unreviewed
CVE-2024-38480
was published
Jul 1, 2024
VM images built with Image Builder with some providers use default credentials during builds in github.com/kubernetes-sigs/image-builder
Moderate
CVE-2024-9594
was published
for
github.com/kubernetes-sigs/image-builder
(Go)
Oct 15, 2024
Use of Hard-coded Credentials vulnerability in Sonatype Nexus Repository has been discovered in...
Moderate
Unreviewed
CVE-2024-5764
was published
Oct 23, 2024
An issue was discovered in UCI IDOL 2 (aka uciIDOL or IDOL2) through 2.12. Data is sent between...
Moderate
Unreviewed
CVE-2024-45165
was published
Aug 22, 2024
ProTip!
Advisories are also available from the
GraphQL API