GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,347
Erlang
31
GitHub Actions
22
Go
2,117
Maven
5,000+
npm
3,768
NuGet
680
pip
3,457
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
441 advisories
Filter by severity
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for...
High
Unreviewed
CVE-2020-14510
was published
May 24, 2022
Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a...
High
Unreviewed
CVE-2022-38420
was published
Oct 15, 2022
Zoom Rooms for macOS clients before version 5.11.4 contain an insecure key generation mechanism....
High
Unreviewed
CVE-2022-36925
was published
Jan 9, 2023
Dell EMC Data Protection Advisor versions 6.4, 6.5 and 18.1 contain an undocumented account with...
High
Unreviewed
CVE-2020-5351
was published
May 24, 2022
The use of multiple hard-coded cryptographic keys in cSRX Series software in Juniper Networks...
High
Unreviewed
CVE-2021-0266
was published
May 24, 2022
An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login...
High
Unreviewed
CVE-2020-14070
was published
May 24, 2022
A CWE-798: Use of Hard-coded Credentials vulnerability exists in the Unity Loader and OS Loader...
High
Unreviewed
CVE-2020-7498
was published
May 24, 2022
The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code...
High
Unreviewed
CVE-2020-13166
was published
May 24, 2022
Some Dahua software products have a vulnerability of using of hard-coded cryptographic key. An...
High
Unreviewed
CVE-2022-45425
was published
Dec 27, 2022
KMS Controls BAC-A1616BC BACnet devices have a cleartext password of snowman in the BACKDOOR_NAME...
High
Unreviewed
CVE-2020-7233
was published
May 24, 2022
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9...
High
Unreviewed
CVE-2018-17767
was published
May 24, 2022
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9...
High
Unreviewed
CVE-2018-17771
was published
May 24, 2022
The express install, which is the suggested way to install Puppet Enterprise, gives the user a...
High
Unreviewed
CVE-2019-10694
was published
May 24, 2022
Premisys Identicard version 3.1.190 contains hardcoded credentials in the WCF service on port...
High
Unreviewed
CVE-2019-3906
was published
May 13, 2022
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 uses ZODB storage without authentication.
High
Unreviewed
CVE-2020-15327
was published
Sep 30, 2022
Premisys Identicard version 3.1.190 stores backup files as encrypted zip files. The password to...
High
Unreviewed
CVE-2019-3908
was published
May 13, 2022
BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited...
High
Unreviewed
CVE-2022-40263
was published
Nov 5, 2022
Nokia Fastmile 3tg00118abad52 devices shipped by Optus are shipped with a default hardcoded admin...
High
Unreviewed
CVE-2022-36222
was published
Dec 21, 2022
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is...
High
Unreviewed
CVE-2021-44720
was published
Aug 13, 2022
A vulnerability has been identified in LOGO!8 BM (All versions). Project data stored on the...
High
Unreviewed
CVE-2019-10920
was published
May 24, 2022
A CWE-798 use of hardcoded credentials vulnerability exists in BMX-NOR-0200H with firmware...
High
Unreviewed
CVE-2019-6812
was published
May 24, 2022
Prima Systems FlexAir devices have Hard-coded Credentials.
High
Unreviewed
CVE-2019-7672
was published
May 24, 2022
A weak default administrator password for the web interface and serial port was reported in some...
High
Unreviewed
CVE-2021-42850
was published
May 19, 2022
MapGIS 10.5 Pro IGServer has hardcoded credentials in the front-end and can lead to escalation of...
High
Unreviewed
CVE-2022-36170
was published
Aug 20, 2022
Penta Security Systems Inc WAPPLES v6.0 r3 4.10-hotfix1 allows attackers to escalate privileges...
High
Unreviewed
CVE-2022-31322
was published
Sep 14, 2022
ProTip!
Advisories are also available from the
GraphQL API