GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
720 advisories
Filter by severity
Hard-coded cryptographic keys in Admin UI of EZCast Pro II version 1.17478.146 allows attackers...
Critical
Unreviewed
CVE-2025-13954
was published
Dec 10, 2025
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected...
Critical
Unreviewed
CVE-2025-40938
was published
Dec 9, 2025
ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
Critical
Unreviewed
CVE-2025-29268
was published
Dec 4, 2025
AstrBot is vulnerable to RCE with hard-coded JWT signing keys
Critical
CVE-2025-55449
was published
for
astrbot
(pip)
Nov 14, 2025
SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or...
Critical
Unreviewed
CVE-2025-42890
was published
Nov 11, 2025
An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security...
Critical
Unreviewed
CVE-2025-6950
was published
Oct 17, 2025
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up...
Critical
Unreviewed
CVE-2025-10850
was published
Oct 16, 2025
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token...
Critical
Unreviewed
CVE-2025-56749
was published
Oct 15, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application...
Critical
Unreviewed
CVE-2025-34209
was published
Sep 29, 2025
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for...
Critical
Unreviewed
CVE-2025-57601
was published
Sep 22, 2025
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined...
Critical
Unreviewed
CVE-2025-57602
was published
Sep 22, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and...
Critical
Unreviewed
CVE-2025-34198
was published
Sep 19, 2025
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to...
Critical
Unreviewed
CVE-2025-8570
was published
Sep 11, 2025
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default...
Critical
Unreviewed
CVE-2025-35451
was published
Sep 5, 2025
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials...
Critical
Unreviewed
CVE-2025-35452
was published
Sep 5, 2025
Clinic Image System developed by Changing contains hard-coded Credentials, allowing...
Critical
Unreviewed
CVE-2025-8857
was published
Aug 29, 2025
Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by...
Critical
Unreviewed
CVE-2025-43982
was published
Aug 13, 2025
Tigo Energy's Cloud Connect Advanced (CCA) device contains hard-coded credentials that allow...
Critical
Unreviewed
CVE-2025-7768
was published
Aug 6, 2025
Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded...
Critical
Unreviewed
CVE-2025-51536
was published
Aug 4, 2025
An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with...
Critical
Unreviewed
CVE-2025-30125
was published
Jul 28, 2025
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows...
Critical
Unreviewed
CVE-2025-54454
was published
Jul 23, 2025
Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows...
Critical
Unreviewed
CVE-2025-54455
was published
Jul 23, 2025
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent...
Critical
Unreviewed
CVE-2024-38648
was published
Jul 12, 2025
An OEM IP camera manufactured by Shenzhen Liandian Communication Technology LTD exposes a Telnet...
Critical
Unreviewed
CVE-2025-7503
was published
Jul 11, 2025
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to...
Critical
Unreviewed
CVE-2025-7401
was published
Jul 11, 2025
ProTip!
Advisories are also available from the
GraphQL API