GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
108
GitHub Actions
54
Go
4,475
Maven
5,000+
npm
5,000+
NuGet
1,091
pip
5,000+
Pub
13
RubyGems
1,144
Rust
1,510
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
1
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
10
1,555 advisories
Filter by severity
A provisioning script used when installing HIPASE-250 (formerly 250
SCALA) engineering...
High
Unreviewed
CVE-2026-65313
was published
Jul 31, 2026
DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability....
Critical
Unreviewed
CVE-2026-18452
was published
Jul 31, 2026
Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET...
Critical
Unreviewed
CVE-2026-52539
was published
Jul 30, 2026
A hard-coded AWS IAM credentials vulnerability
in Koollab LMS allowed
an attacker to access...
Moderate
Unreviewed
CVE-2026-63239
was published
Jul 29, 2026
IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to...
High
Unreviewed
CVE-2026-13463
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs...
High
Unreviewed
CVE-2021-32085
was published
Jul 28, 2026
An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs...
High
Unreviewed
CVE-2021-32087
was published
Jul 28, 2026
A hardcoded credential
vulnerability exists in the firmware of multiple TP-Link routers (TL...
Moderate
Unreviewed
CVE-2026-12001
was published
Jul 27, 2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential...
Moderate
Unreviewed
CVE-2025-59180
was published
Jul 27, 2026
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide...
Critical
Unreviewed
CVE-2026-65879
was published
Jul 27, 2026
Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51...
Critical
Unreviewed
CVE-2026-8982
was published
Jul 21, 2026
Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token...
Critical
Unreviewed
CVE-2026-8983
was published
Jul 21, 2026
LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection
Critical
CVE-2026-61740
was published
for
lightrag-hku
(pip)
Jul 20, 2026
IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or...
Critical
Unreviewed
CVE-2026-13446
was published
Jul 17, 2026
Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise
Critical
CVE-2026-55579
was published
for
pheditor/pheditor
(Composer)
Jul 16, 2026
ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing...
Critical
Unreviewed
CVE-2026-14807
was published
Jul 6, 2026
Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious...
Critical
Unreviewed
CVE-2026-13768
was published
Jul 3, 2026
In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded...
Moderate
Unreviewed
CVE-2026-13728
was published
Jul 3, 2026
9router's Hardcoded Default fallback JWT Secret Allows Authentication Bypass
Critical
CVE-2026-49352
was published
for
9router
(npm)
Jul 2, 2026
UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded...
Critical
Unreviewed
CVE-2026-7839
was published
Jul 1, 2026
Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ...
Critical
Unreviewed
CVE-2026-56278
was published
Jul 1, 2026
Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services...
Critical
Unreviewed
CVE-2026-50110
was published
Jul 1, 2026
The DMP-5000 devices are shipped with a default administrative web account with weak...
Critical
Unreviewed
CVE-2026-31928
was published
Jun 27, 2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8...
High
Unreviewed
CVE-2026-12628
was published
Jun 22, 2026
Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default...
Critical
Unreviewed
CVE-2026-56265
was published
Jun 21, 2026
ProTip!
Advisories are also available from the
GraphQL API