GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
76 advisories
Filter by severity
PowerJob Server version 5.1.2 (and likely earlier) uses a predictable JWT signing key for HS256...
Critical
Unreviewed
CVE-2026-75431
was published
Sep 4, 2026
An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a...
Critical
Unreviewed
CVE-2026-51977
was published
Aug 18, 2026
Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy...
Critical
Unreviewed
CVE-2026-14804
was published
Aug 4, 2026
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web...
Critical
Unreviewed
CVE-2026-18753
was published
Aug 4, 2026
The
product firmware contains an embedded, static RSA private key utilized by the
Lighttpd web...
Critical
Unreviewed
CVE-2026-18754
was published
Aug 4, 2026
Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a...
Critical
Unreviewed
CVE-2026-16504
was published
Jul 31, 2026
CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows...
Critical
Unreviewed
CVE-2026-54363
was published
Jul 30, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a...
Critical
Unreviewed
CVE-2021-32086
was published
Jul 28, 2026
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT...
Critical
Unreviewed
CVE-2026-56271
was published
Jul 12, 2026
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass...
Critical
Unreviewed
CVE-2026-35019
was published
Jun 23, 2026
Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt...
Critical
Unreviewed
CVE-2026-28742
was published
Jun 12, 2026
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same...
Critical
Unreviewed
CVE-2026-50091
was published
Jun 12, 2026
praisonai-platform: JWT signing key defaults to hardcoded "dev-secret-change-me", allowing token forgery for any user when PLATFORM_ENV is unset
Critical
CVE-2026-47410
was published
for
praisonai-platform
(pip)
May 29, 2026
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote...
Critical
Unreviewed
CVE-2026-9642
was published
May 26, 2026
HAXcms: Private Key Disclosure via Broken HMAC Implementation
Critical
CVE-2026-46395
was published
for
@haxtheweb/haxcms-nodejs
(npm)
May 19, 2026
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache...
Critical
Unreviewed
CVE-2026-31986
was published
May 19, 2026
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Critical
Unreviewed
CVE-2026-32644
was published
Apr 28, 2026
Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small...
Critical
Unreviewed
CVE-2025-67112
was published
Mar 19, 2026
In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for...
Critical
Unreviewed
CVE-2025-67305
was published
Feb 19, 2026
Calero VeraSMART versions prior to 2022 R1 use static ASP.NET/IIS machineKey values configured...
Critical
Unreviewed
CVE-2026-26335
was published
Feb 13, 2026
User credentials are stored using AES‑ECB encryption with a hardcoded key. An unauthenticated...
Critical
Unreviewed
CVE-2026-22906
was published
Feb 9, 2026
FUXA Unauthenticated Remote Code Execution via Hardcoded JWT Secret in Default Configuration
Critical
CVE-2026-25894
was published
for
fuxa-server
(npm)
Feb 5, 2026
Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication
Critical
CVE-2026-25505
was published
for
bambuddy
(pip)
Feb 2, 2026
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages,...
Critical
Unreviewed
CVE-2026-22586
was published
Jan 24, 2026
Delta Electronics DIAView has multiple vulnerabilities.
Critical
Unreviewed
CVE-2025-62581
was published
Jan 16, 2026
ProTip!
Advisories are also available from the
GraphQL API