GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,822
Erlang
36
GitHub Actions
32
Go
2,413
Maven
5,000+
npm
4,052
NuGet
723
pip
3,844
Pub
12
RubyGems
933
Rust
1,005
Swift
38
Unreviewed advisories
All unreviewed
5,000+
206 advisories
Filter by severity
A vulnerability was discovered in the storage policy for certain sets of encryption keys in the...
Moderate
Unreviewed
CVE-2025-37112
was published
Jul 31, 2025
A vulnerability was discovered in the storage policy for certain sets of authentication keys in...
Moderate
Unreviewed
CVE-2025-37111
was published
Jul 31, 2025
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and...
Moderate
Unreviewed
CVE-2021-22126
was published
Mar 17, 2025
An insecure sensitive key storage issue was found in MyASUS. potentially allowing unauthorized...
Moderate
Unreviewed
CVE-2025-4570
was published
Jul 21, 2025
Use of Hard-coded Credentials in TP-Link Archer C50 V3(
<=
180703)/V4(
<=
250117
)/V5(
...
Moderate
Unreviewed
CVE-2025-6982
was published
Jul 16, 2025
This vulnerability exists in Digisol DG-GR6821AC Router due to hard-coded Root Access Credentials...
Moderate
Unreviewed
CVE-2025-53754
was published
Jul 16, 2025
Use of hard-coded credentials issue exists in ZWX-2000CSW2-HN prior to 0.3.19 and ZWX-2000CS2-HN...
Moderate
Unreviewed
CVE-2025-53842
was published
Jul 16, 2025
Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file...
Moderate
Unreviewed
CVE-2025-52363
was published
Jul 14, 2025
WOLFBOX Level 2 EV Charger Management Card Hard-coded Credentials Authentication Bypass...
Moderate
Unreviewed
CVE-2025-5751
was published
Jun 6, 2025
Android Spoon application version 7.11.1 to 8.6.0 uses hard-coded credentials, which may allow a...
Moderate
Unreviewed
CVE-2024-23453
was published
Jan 24, 2024
A vulnerability has been found in PerfreeBlog 4.0.11 and classified as problematic. This...
Moderate
Unreviewed
CVE-2025-5164
was published
May 26, 2025
A technical user has hardcoded credentials in Wallstreet Suite TRM 7.4.83 (64-bit edition) with...
Moderate
Unreviewed
CVE-2021-41320
was published
May 24, 2022
Default credentials were present in the web portal for Airpointer 2.4.107-2, allowing an...
Moderate
Unreviewed
CVE-2025-4633
was published
May 30, 2025
Dell PowerStore, version(s) 4.0.0.0, contain(s) an Use of Hard-coded Credentials vulnerability in...
Moderate
Unreviewed
CVE-2025-36572
was published
May 28, 2025
Iridium Certus 700 version 1.0.1 has an embedded credentials vulnerability in the code. This...
Moderate
Unreviewed
CVE-2025-41380
was published
May 23, 2025
Medtronic Valleylab Exchange Client version 3.4 and below, Valleylab FT10 Energy Platform ...
Moderate
Unreviewed
CVE-2019-13543
was published
May 24, 2022
There are several scripts in the web interface that are accessible via undocumented hard-coded...
Moderate
Unreviewed
CVE-2025-48414
was published
May 21, 2025
ConnectWise-Password-Encryption-Utility.exe in ConnectWise Risk Assessment allows an attacker to...
Moderate
Unreviewed
CVE-2025-4876
was published
May 19, 2025
The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in...
Moderate
Unreviewed
CVE-2024-13688
was published
Apr 28, 2025
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to...
Moderate
Unreviewed
CVE-2025-27488
was published
May 13, 2025
The TeleMessage archiving backend through 2025-05-05 accepts API calls (to request an...
Moderate
Unreviewed
CVE-2025-47730
was published
May 8, 2025
CWE-798: Use of Hard-coded Credentials
Moderate
Unreviewed
CVE-2025-23179
was published
Apr 29, 2025
A Use of Hard-Coded Cryptographic Key issue was discovered in Mirion Technologies DMC 3000...
Moderate
Unreviewed
CVE-2017-9649
was published
May 13, 2022
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all...
Moderate
Unreviewed
CVE-2017-6039
was published
May 13, 2022
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. A...
Moderate
Unreviewed
CVE-2024-22083
was published
Mar 20, 2024
ProTip!
Advisories are also available from the
GraphQL API