GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,782
NuGet
683
pip
3,460
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
543 advisories
Filter by severity
An issue was discovered on the D-Link DWR-932B router. Undocumented TELNET and SSH services...
Critical
Unreviewed
CVE-2016-10177
was published
May 13, 2022
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have...
Critical
Unreviewed
CVE-2016-10307
was published
May 13, 2022
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx...
Critical
Unreviewed
CVE-2016-10305
was published
May 13, 2022
MaLion for Windows and Mac versions 3.2.1 to 5.2.1 uses a hardcoded cryptographic key which may...
Critical
Unreviewed
CVE-2017-10818
was published
May 13, 2022
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an...
Critical
Unreviewed
CVE-2017-6558
was published
May 13, 2022
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username...
Critical
Unreviewed
CVE-2017-7576
was published
May 13, 2022
EMC ViPR SRM, EMC Storage M&R, EMC VNX M&R, EMC M&R for SAS Solution Packs (EMC ViPR SRM prior to...
Critical
Unreviewed
CVE-2017-8011
was published
May 13, 2022
A vulnerability exists in Schneider Electric's Pelco Sarix Professional in all firmware versions...
Critical
Unreviewed
CVE-2018-7229
was published
May 13, 2022
Schneider Electric SoMachine Basic 1.4 SP1 and Schneider Electric Modicon TM221CE16R 1.3.3.3...
Critical
Unreviewed
CVE-2017-7574
was published
May 13, 2022
An exploitable unsafe default configuration vulnerability exists in the TURN server function of...
Critical
Unreviewed
CVE-2018-4059
was published
May 13, 2022
An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless...
Critical
Unreviewed
CVE-2016-8717
was published
May 13, 2022
Hard-coded FTP credentials (r:r) are included in the Foscam C1 running firmware 1.9.1.12....
Critical
Unreviewed
CVE-2016-8731
was published
May 13, 2022
IBM Spectrum Virtualize 8.2, 8.3, and 8.4 could allow an attacker to allow unauthorized access...
Critical
Unreviewed
CVE-2021-38969
was published
May 12, 2022
** UNSUPPORTED WHEN ASSIGNED ** QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in...
Critical
Unreviewed
CVE-2013-6276
was published
May 5, 2022
An issue was discovered on MOBOTIX S14 MX-V4.2.1.61 devices. There is a default password of...
Critical
Unreviewed
CVE-2009-5154
was published
May 2, 2022
In Bender/ebee Charge Controllers in multiple versions are prone to Hardcoded Credentials. Bender...
Critical
Unreviewed
CVE-2021-34601
was published
Apr 28, 2022
An authentication bypass vulnerability exists in the device password generation functionality of...
Critical
Unreviewed
CVE-2021-40422
was published
Apr 15, 2022
An authentication bypass vulnerability exists in the Web Application functionality of Moxa MXView...
Critical
Unreviewed
CVE-2021-40390
was published
Apr 15, 2022
A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1,...
Critical
Unreviewed
CVE-2022-23441
was published
Apr 7, 2022
On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21,...
Critical
Unreviewed
CVE-2021-30064
was published
Apr 5, 2022
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across...
Critical
Unreviewed
CVE-2022-25569
was published
Apr 5, 2022
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP...
Critical
Unreviewed
CVE-2022-1162
was published
Apr 5, 2022
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded...
Critical
Unreviewed
CVE-2022-24693
was published
Mar 31, 2022
UNNO v03.11.00 was discovered to contain access control issue.
Critical
Unreviewed
CVE-2022-25521
was published
Mar 30, 2022
ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite...
Critical
Unreviewed
CVE-2022-25577
was published
Mar 26, 2022
ProTip!
Advisories are also available from the
GraphQL API