GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
259 advisories
Filter by severity
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and...
High
Unreviewed
CVE-2026-80114
was published
Sep 4, 2026
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256...
Critical
Unreviewed
CVE-2026-75431
was published
Sep 4, 2026
A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4....
Moderate
Unreviewed
CVE-2026-18330
was published
Sep 4, 2026
WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass...
Moderate
Unreviewed
CVE-2026-84483
was published
Sep 2, 2026
NVIDIA UFM Enterprise contains a vulnerability in the session management component, where an...
Moderate
Unreviewed
CVE-2026-24166
was published
Aug 25, 2026
The use of
hard-coded cryptographic key vulnerability has been identified in the mesh...
High
Unreviewed
CVE-2026-15469
was published
Aug 24, 2026
act starts an HTTP Artifacts V4 backend whenever a workflow uses actions/upload-artifact@v4 or...
High
Unreviewed
CVE-2026-76847
was published
Aug 24, 2026
In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway...
Moderate
Unreviewed
CVE-2026-76258
was published
Aug 20, 2026
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a...
Critical
Unreviewed
CVE-2026-51977
was published
Aug 18, 2026
Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows :...
High
Unreviewed
CVE-2026-64887
was published
Aug 14, 2026
IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid...
Moderate
Unreviewed
CVE-2026-17468
was published
Aug 13, 2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo...
High
Unreviewed
CVE-2026-63423
was published
Aug 13, 2026
is affected by a Use of Hard-coded Cryptographic Key vulnerability that could result in a...
High
Unreviewed
CVE-2026-34635
was published
Aug 11, 2026
A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products...
High
Unreviewed
CVE-2026-57262
was published
Aug 11, 2026
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials...
High
Unreviewed
CVE-2026-66763
was published
Aug 11, 2026
In affected TP-Link Aginet devices, use of
hardcoded cryptographic keys embedded in the firmware...
High
Unreviewed
CVE-2025-30239
was published
Aug 11, 2026
Use of hard-coded cryptographic key vulnerability in Tobit Laboratories AG TeamDavid's Webbox....
High
Unreviewed
CVE-2026-54218
was published
Aug 7, 2026
By accessing unencrypted information in the device firmware, an attacker can obtain credentials...
Moderate
Unreviewed
CVE-2026-49008
was published
Aug 7, 2026
By accessing unencrypted information in the device firmware, an attacker can obtain credentials...
Moderate
Unreviewed
CVE-2026-49006
was published
Aug 7, 2026
The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared...
High
Unreviewed
CVE-2026-18411
was published
Aug 5, 2026
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy...
Critical
Unreviewed
CVE-2026-14804
was published
Aug 4, 2026
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web...
Critical
Unreviewed
CVE-2026-18753
was published
Aug 4, 2026
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web...
Critical
Unreviewed
CVE-2026-18754
was published
Aug 4, 2026
A cryptographic
weakness exists in the Omada adoption protocol.
The protocol relies on hard...
Moderate
Unreviewed
CVE-2025-15627
was published
Aug 3, 2026
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a...
Critical
Unreviewed
CVE-2026-16504
was published
Jul 31, 2026
ProTip!
Advisories are also available from the
GraphQL API