GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
720 advisories
Filter by severity
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85148
was published
Sep 4, 2026
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-85146
was published
Sep 4, 2026
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that...
Critical
Unreviewed
CVE-2026-85391
was published
Sep 3, 2026
Use of Hard-coded Credentials vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft...
Critical
Unreviewed
CVE-2026-18931
was published
Sep 1, 2026
Insecure hardcoded credentials in the Admin account of Tenda HG21 V4.0.0-260302 allows attackers...
Critical
Unreviewed
CVE-2026-38577
was published
Aug 31, 2026
Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that...
Critical
Unreviewed
CVE-2026-82448
was published
Aug 29, 2026
DJI drones contain an FTP service that uses hardcoded credentials shared across affected models...
Critical
Unreviewed
CVE-2026-78251
was published
Aug 27, 2026
Use of Hard-coded Credentials vulnerability in TÜBİTAK BİLGEM Software Technologies Research...
Critical
Unreviewed
CVE-2026-75896
was published
Aug 26, 2026
Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret...
Critical
Unreviewed
CVE-2026-71960
was published
Aug 19, 2026
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector...
Critical
Unreviewed
CVE-2021-43717
was published
Aug 18, 2026
Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before...
Critical
Unreviewed
CVE-2026-19871
was published
Aug 14, 2026
CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI...
Critical
Unreviewed
CVE-2026-67614
was published
Aug 13, 2026
CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an...
Critical
Unreviewed
CVE-2026-59507
was published
Aug 13, 2026
WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every...
Critical
Unreviewed
CVE-2026-73519
was published
Aug 13, 2026
The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive...
Critical
Unreviewed
CVE-2026-67568
was published
Aug 12, 2026
MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in...
Critical
Unreviewed
CVE-2026-69102
was published
Aug 11, 2026
A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an...
Critical
Unreviewed
CVE-2025-13293
was published
Aug 10, 2026
My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication...
Critical
Unreviewed
CVE-2025-63823
was published
Aug 6, 2026
DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py...
Critical
Unreviewed
CVE-2026-71238
was published
Aug 5, 2026
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-18452
was published
Jul 31, 2026
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET...
Critical
Unreviewed
CVE-2026-52539
was published
Jul 30, 2026
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide...
Critical
Unreviewed
CVE-2026-65879
was published
Jul 27, 2026
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token...
Critical
Unreviewed
CVE-2026-8983
was published
Jul 21, 2026
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51...
Critical
Unreviewed
CVE-2026-8982
was published
Jul 21, 2026
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
ProTip!
Advisories are also available from the
GraphQL API