GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
430 advisories
Filter by severity
Precor touchscreen console P82 contains a private SSH key that corresponds to a default public...
High
Unreviewed
CVE-2023-49222
was published
Jun 7, 2024
Precor touchscreen console P62, P80, and P82 could allow a remote attacker to obtain sensitive...
High
Unreviewed
CVE-2023-49223
was published
Jun 7, 2024
Precor touchscreen console P62, P80, and P82 contains a default SSH public key in the...
High
Unreviewed
CVE-2023-49224
was published
Jun 7, 2024
D-Link DIR-605L v2.13B01 was discovered to contain a hardcoded password vulnerability in /etc...
High
Unreviewed
CVE-2024-37630
was published
Jun 13, 2024
ZWX-2000CSW2-HN firmware versions prior to Ver.0.3.15 uses hard-coded credentials, which may...
High
Unreviewed
CVE-2024-39838
was published
Aug 5, 2024
Precor touchscreen console P62, P80, and P82 could allow a remote attacker (within the local...
High
Unreviewed
CVE-2023-49221
was published
Jun 7, 2024
TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the...
High
Unreviewed
CVE-2024-34219
was published
May 14, 2024
Use of hard-coded credentials vulnerability affecting Vonets industrial wifi bridge relays and...
High
Unreviewed
CVE-2024-41161
was published
Aug 8, 2024
D-Link DIR-300 REVA FIRMWARE v1.06B05_WW contains hardcoded credentials in the Telnet service.
High
Unreviewed
CVE-2024-41616
was published
Aug 6, 2024
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the...
High
Unreviewed
CVE-2019-20471
was published
May 24, 2022
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover...
High
Unreviewed
CVE-2024-5471
was published
Jul 17, 2024
It was observed that all the Toshiba printers contain credentials used for WebDAV access in the...
High
Unreviewed
CVE-2024-27170
was published
Jun 14, 2024
It appears that some hardcoded keys are used for authentication to internal API. Knowing these...
High
Unreviewed
CVE-2024-27168
was published
Jun 14, 2024
The configuration file is encrypted with a static key derived from a
static five-character...
High
Unreviewed
CVE-2024-36496
was published
Jun 24, 2024
'OfferBox' App for Android versions 2.0.0 to 2.3.17 and 'OfferBox' App for iOS versions 2.1.7 to...
High
Unreviewed
CVE-2024-32988
was published
May 22, 2024
Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST...
High
Unreviewed
CVE-2023-26566
was published
May 14, 2024
In KDE libksieve before 23.03.80, kmanagesieve/session.cpp places a cleartext password in server...
High
Unreviewed
CVE-2023-52723
was published
Apr 29, 2024
A vulnerability in the default configuration of the Simple Network
Management Protocol (SNMP)...
High
Unreviewed
CVE-2024-5460
was published
Jun 26, 2024
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor....
High
Unreviewed
CVE-2024-6045
was published
Jun 17, 2024
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege...
High
Unreviewed
CVE-2024-0865
was published
Jun 12, 2024
Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials...
High
Unreviewed
CVE-2024-29170
was published
Jun 4, 2024
FlyteAdmin's Default OAuth Authorization Server secret must be rotated
High
CVE-2022-39273
was published
for
github.com/flyteorg/flyteadmin
(Go)
Oct 5, 2022
Hardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5...
High
Unreviewed
CVE-2024-4844
was published
May 16, 2024
The SolarWinds Access Rights Manager was found to contain a hard-coded credential authentication...
High
Unreviewed
CVE-2024-23473
was published
May 14, 2024
Voltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation...
High
Unreviewed
CVE-2023-51588
was published
May 3, 2024
ProTip!
Advisories are also available from the
GraphQL API