GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
                  
                    
                      
                      All reviewed
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      Composer
                    
                    
                      4,968
                    
                  
                  
                    
                      
                      Erlang
                    
                    
                      39
                    
                  
                  
                    
                      
                      GitHub Actions
                    
                    
                      38
                    
                  
                  
                    
                      
                      Go
                    
                    
                      2,616
                    
                  
                  
                    
                      
                      Maven
                    
                    
                      5,000+
                    
                  
                  
                    
                      
                      npm
                    
                    
                      4,255
                    
                  
                  
                    
                      
                      NuGet
                    
                    
                      760
                    
                  
                  
                    
                      
                      pip
                    
                    
                      4,040
                    
                  
                  
                    
                      
                      Pub
                    
                    
                      12
                    
                  
                  
                    
                      
                      RubyGems
                    
                    
                      953
                    
                  
                  
                    
                      
                      Rust
                    
                    
                      1,050
                    
                  
                  
                    
                      
                      Swift
                    
                    
                      45
                    
                  
                  Unreviewed advisories
                  
                    
                      
                      All unreviewed
                    
                    
                      5,000+
                    
                  
            130 advisories
        Filter by severity
        
      
      
    
                    
                      RUCKUS Network Director (RND) before 4.5 allows jailed users to obtain root access vis a weak,...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-44955
                      
                      was published
                      Aug 4, 2025 
                    
                  
                    
                      Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.1002 Application 20.0...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-27638
                      
                      was published
                      Mar 5, 2025 
                    
                  
                    
                      Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-5405
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47818
                      
                      was published
                      Jun 27, 2025 
                    
                  
                    
                      A vulnerability was determined in Tenda F1202 1.2.0.9/1.2.0.14/1.2.0.20. Impacted is an unknown...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9806
                      
                      was published
                      Oct 21, 2025 
                    
                  
                    
                      A hard-coded weak password vulnerability has been discovered in all Magic-branded devices from...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-61330
                      
                      was published
                      Oct 16, 2025 
                    
                  
                    
                      A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. Affected by this...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11643
                      
                      was published
                      Oct 12, 2025 
                    
                  
                    
                      A hard-coded, non-random password for the object store (minio) of KNIME Business Hub in all...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-2402
                      
                      was published
                      Mar 31, 2025 
                    
                  
                    
                      Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2014-2363
                      
                      was published
                      May 17, 2022 
                    
                  
                    
                      Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-1228
                      
                      was published
                      Jun 10, 2024 
                    
                  
                    
                      Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-3699
                      
                      was published
                      Jun 10, 2024 
                    
                  
                    
                      Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-3700
                      
                      was published
                      Jun 10, 2024 
                    
                  
                    
                      Use of a hard-coded password for a database administrator account created during Wapro ERP...
                    
                      
  Critical
                      
                        Unreviewed
                    
                
                      
                        CVE-2024-4996
                      
                      was published
                      Dec 18, 2024 
                    
                  
                    
                      Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47821
                      
                      was published
                      Jun 27, 2025 
                    
                  
                    
                      Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-47823
                      
                      was published
                      Jun 27, 2025 
                    
                  
                    
                      A security flaw has been discovered in Apeman ID71 218.53.203.117. This vulnerability affects...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-11126
                      
                      was published
                      Sep 29, 2025 
                    
                  
                    
                      An attacker with adjacent access, without authentication, can exploit 
this vulnerability to...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-54754
                      
                      was published
                      Sep 18, 2025 
                    
                  
                    
                      A vulnerability was determined in yeqifu carRental up to 3fabb7eae93d209426638863980301d6f99866b3...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9310
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      A security vulnerability has been detected in Tenda W12 up to 3.0.0.6(3948). Affected is an...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9778
                      
                      was published
                      Sep 2, 2025 
                    
                  
                    
                      A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted element is an unknown...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9731
                      
                      was published
                      Aug 31, 2025 
                    
                  
                    
                      Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-58081
                      
                      was published
                      Aug 28, 2025 
                    
                  
                    
                      A vulnerability was identified in FNKvision Y215 CCTV Camera 10.194.120.40. Affected by this...
                    
                      
  High
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9380
                      
                      was published
                      Aug 24, 2025 
                    
                  
                    
                      A vulnerability was found in Tenda AC10 16.03.10.13. Affected is an unknown function of the file ...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9309
                      
                      was published
                      Aug 21, 2025 
                    
                  
                    
                      An issue was discovered in Commvault before 11.36.60. A vulnerability in a known login mechanism...
                    
                      
  Moderate
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-57788
                      
                      was published
                      Aug 20, 2025 
                    
                  
                    
                      A security flaw has been discovered in Tenda AC20 16.03.08.12. Affected by this vulnerability is...
                    
                      
  Low
                      
                        Unreviewed
                    
                
                      
                        CVE-2025-9091
                      
                      was published
                      Aug 17, 2025 
                    
                  
        
        ProTip!
        Advisories are also available from the 
        GraphQL API