GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,598 advisories
Filter by severity
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded...
High
Unreviewed
CVE-2026-77847
was published
Sep 4, 2026
IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a...
Moderate
Unreviewed
CVE-2026-5522
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85148
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Moderate
Unreviewed
CVE-2026-85149
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85146
was published
Sep 4, 2026
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the...
High
Unreviewed
CVE-2026-85451
was published
Sep 4, 2026
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that...
Critical
Unreviewed
CVE-2026-85391
was published
Sep 3, 2026
A data exposure vulnerability exists in the affected product. There are hardcoded links in the...
High
Unreviewed
CVE-2024-7952
was published
Sep 1, 2026
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft...
Critical
Unreviewed
CVE-2026-18931
was published
Sep 1, 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers...
Critical
Unreviewed
CVE-2026-38577
was published
Aug 31, 2026
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that...
Critical
Unreviewed
CVE-2026-82448
was published
Aug 29, 2026
The vulnerability allows the unauthorised generation of physical access QR codes due to the use...
High
Unreviewed
CVE-2026-12587
was published
Aug 28, 2026
This vulnerability exists in the CP Plus CP-XR-DE21-S Router due to the presence of hardcoded...
High
Unreviewed
CVE-2026-19412
was published
Aug 28, 2026
Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable...
Moderate
Unreviewed
CVE-2026-71396
was published
Aug 28, 2026
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to...
High
Unreviewed
CVE-2026-37012
was published
Aug 27, 2026
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models...
Critical
Unreviewed
CVE-2026-78251
was published
Aug 27, 2026
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
Critical
Unreviewed
CVE-2026-75896
was published
Aug 26, 2026
FA-50 all versions contain hard-coded credentials.
An attacker, who knows the credentials and has...
High
Unreviewed
CVE-2026-59769
was published
Aug 25, 2026
Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to...
Moderate
Unreviewed
CVE-2026-76131
was published
Aug 21, 2026
In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk...
Moderate
Unreviewed
CVE-2026-76392
was published
Aug 20, 2026
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret...
Critical
Unreviewed
CVE-2026-71960
was published
Aug 19, 2026
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector...
Critical
Unreviewed
CVE-2021-43717
was published
Aug 18, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py...
High
Unreviewed
CVE-2026-74893
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone...
High
Unreviewed
CVE-2026-74892
was published
Aug 17, 2026
openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server...
High
Unreviewed
CVE-2026-74891
was published
Aug 17, 2026
ProTip!
Advisories are also available from the
GraphQL API