GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,788
Maven
5,000+
npm
5,000+
NuGet
1,124
pip
5,000+
Pub
13
RubyGems
1,152
Rust
1,576
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
20
1,622 advisories
Filter by severity
The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server...
Moderate
Unreviewed
CVE-2026-86555
was published
Sep 20, 2026
IBM Guardium Data Protection 12.2 is vulnerable to a hardcoded credentials vulnerability in the...
High
Unreviewed
CVE-2026-84034
was published
Sep 18, 2026
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time...
Moderate
Unreviewed
CVE-2026-77960
was published
Sep 18, 2026
Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time...
High
Unreviewed
CVE-2026-86520
was published
Sep 18, 2026
AnyCable: Telemetry Subsystem Contains Hardcoded Authentication Token and Transmits CLI Arguments Including Secrets
Moderate
CVE-2026-63406
was published
for
github.com/anycable/anycable
(Go)
Sep 18, 2026
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded...
High
Unreviewed
CVE-2026-81440
was published
Sep 17, 2026
Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity,...
Critical
Unreviewed
CVE-2026-92787
was published
Sep 16, 2026
The affected products use hard-coded credentials, which could allow an attacker to run the ftpd...
High
Unreviewed
CVE-2026-68950
was published
Sep 15, 2026
The affected products use hard-coded credentials, which could allow remote access to files with...
Critical
Unreviewed
CVE-2026-66890
was published
Sep 15, 2026
TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root...
Critical
Unreviewed
CVE-2026-37152
was published
Sep 15, 2026
Use of hardcoded default credentials in Xiongmai IP Camera XM530 firmware HMT.CM2005-v220608.1837...
Critical
Unreviewed
CVE-2026-79396
was published
Sep 11, 2026
Central Dogma: Hard-coded ZooKeeper replication secret 'ch4n63m3' with silent fallback enables cluster takeover
Critical
CVE-2026-11746
was published
for
com.linecorp.centraldogma:centraldogma-server
(Maven)
Sep 11, 2026
The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An...
High
Unreviewed
CVE-2026-85083
was published
Sep 11, 2026
A vulnerability was reported in Lenovo Health Android Application, distributed exclusively in the...
Critical
Unreviewed
CVE-2026-75940
was published
Sep 10, 2026
There is an Improper Encryption Configuration Vulnerability in some Hikvision Intercom Products....
Moderate
Unreviewed
CVE-2026-85544
was published
Sep 10, 2026
DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component....
Moderate
Unreviewed
CVE-2026-17038
was published
Sep 10, 2026
An issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded...
Critical
Unreviewed
CVE-2026-71801
was published
Sep 9, 2026
An attacker could derive the camera's Wi-Fi password and connect to its wireless network. This...
High
Unreviewed
CVE-2026-81640
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79738
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79740
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-79950
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-79731
was published
Sep 9, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
Moderate
Unreviewed
CVE-2026-80170
was published
Sep 7, 2026
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior...
High
Unreviewed
CVE-2026-80134
was published
Sep 7, 2026
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded...
High
Unreviewed
CVE-2026-77847
was published
Sep 4, 2026
ProTip!
Advisories are also available from the
GraphQL API