GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,752
Maven
5,000+
npm
4,357
NuGet
765
pip
4,121
Pub
12
RubyGems
961
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,376 advisories
Filter by severity
Hardcoded credentials in gsigel14 ATLAS-EPIC commit f29312c (2025-05-26).
Moderate
Unreviewed
CVE-2025-60639
was published
Oct 16, 2025
The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up...
Critical
Unreviewed
CVE-2025-10850
was published
Oct 16, 2025
Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token...
Critical
Unreviewed
CVE-2025-56749
was published
Oct 15, 2025
IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10...
High
Unreviewed
CVE-2025-36087
was published
Oct 13, 2025
Allstar Reviewbot has Authentication Bypass via Hard-coded Webhook Secret
Moderate
CVE-2025-61926
was published
for
github.com/ossf/allstar
(Go)
Oct 10, 2025
Use of Hard-coded Credentials vulnerability in Logo Software Inc. TigerWings ERP allows Read...
Moderate
Unreviewed
CVE-2025-10609
was published
Oct 3, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to 22.0.862 and Application...
Critical
Unreviewed
CVE-2025-34209
was published
Sep 29, 2025
In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active...
High
Unreviewed
CVE-2025-58385
was published
Sep 26, 2025
Use of Hard-coded Credentials vulnerability in Essekia Helpie FAQ allows Retrieve Embedded...
Moderate
Unreviewed
CVE-2025-58659
was published
Sep 22, 2025
Use of Hard-coded Credentials vulnerability in Risto Niinemets Estonian Shipping Methods for...
Moderate
Unreviewed
CVE-2025-58656
was published
Sep 22, 2025
Use of Hard-coded Credentials vulnerability in weDevs WP Project Manager allows Retrieve Embedded...
Moderate
Unreviewed
CVE-2025-58269
was published
Sep 22, 2025
Insufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined...
Critical
Unreviewed
CVE-2025-57602
was published
Sep 22, 2025
AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for...
Critical
Unreviewed
CVE-2025-57601
was published
Sep 22, 2025
Hardcoded credentials in default configuration of PPress 0.0.9.
High
Unreviewed
CVE-2025-52159
was published
Sep 19, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951,...
High
Unreviewed
CVE-2025-34197
was published
Sep 19, 2025
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and...
Critical
Unreviewed
CVE-2025-34198
was published
Sep 19, 2025
Use of Hard-coded Credentials vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3...
High
Unreviewed
CVE-2024-48842
was published
Sep 17, 2025
An issue in H3C Magic M Device M2V100R006 allows a remote attacker to execute arbitrary code via...
High
Unreviewed
CVE-2025-57578
was published
Sep 12, 2025
An issue in H3C Device R365V300R004 allows a remote attacker to execute arbitrary code via the...
High
Unreviewed
CVE-2025-57577
was published
Sep 12, 2025
An issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to...
High
Unreviewed
CVE-2025-57579
was published
Sep 12, 2025
The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to...
Critical
Unreviewed
CVE-2025-8570
was published
Sep 11, 2025
Hardcoded credentials in Dietly v1.25.0 for android allows attackers to gain sensitive information.
High
Unreviewed
CVE-2025-56466
was published
Sep 10, 2025
A vulnerability was identified in Cudy LT500E up to 2.3.12. Affected is an unknown function of...
Low
Unreviewed
CVE-2025-9725
was published
Sep 5, 2025
PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default...
Critical
Unreviewed
CVE-2025-35451
was published
Sep 5, 2025
ProTip!
Advisories are also available from the
GraphQL API