GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
171 advisories
Filter by severity
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an...
Moderate
Unreviewed
CVE-2021-34757
was published
May 24, 2022
An issue was discovered in Aviatrix Controller before 5.4.1204. It contains credentials unused by...
Moderate
Unreviewed
CVE-2020-13414
was published
May 24, 2022
A CWE-798: Use of Hard-coded Credentials vulnerability exists in Vijeo Designer Basic (V1.1...
Moderate
Unreviewed
CVE-2020-7501
was published
May 24, 2022
Multiple vulnerabilities in Cisco Business 220 Series Smart Switches firmware could allow an...
Moderate
Unreviewed
CVE-2021-34744
was published
May 24, 2022
The ifmap service that comes bundled with Juniper Networks Contrail releases uses hard coded...
Moderate
Unreviewed
CVE-2017-10616
was published
May 13, 2022
The client (aka GalaxyClientService.exe) in GOG GALAXY 2.0.19 allows local privilege escalation...
Moderate
Unreviewed
CVE-2020-24574
was published
May 24, 2022
In projectworlds Online Book Store 1.0 Use of Hard-coded Credentials in source code leads to...
Moderate
Unreviewed
CVE-2020-24115
was published
May 24, 2022
Studyplus App for Android v6.3.7 and earlier and Studyplus App for iOS v8.29.0 and earlier use a...
Moderate
Unreviewed
CVE-2020-5667
was published
May 24, 2022
Panasonic Security System WV-S2231L 4.25 has an insecure hard-coded password of lkjhgfdsa (which...
Moderate
Unreviewed
CVE-2020-29193
was published
May 24, 2022
A vulnerability has been identified in SCALANCE X-300 switch family (incl. X408 and SIPLUS NET...
Moderate
Unreviewed
CVE-2020-28395
was published
May 24, 2022
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3),...
Moderate
Unreviewed
CVE-2020-25231
was published
May 24, 2022
Use of a Hard-coded Password in VNCserver in Amino Communications AK45x series, AK5xx series,...
Moderate
Unreviewed
CVE-2020-10206
was published
May 24, 2022
A vulnerability has been identified in SCALANCE X-200 switch family (incl. SIPLUS NET variants) ...
Moderate
Unreviewed
CVE-2020-28391
was published
May 24, 2022
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local...
Moderate
Unreviewed
CVE-2020-0019
was published
May 24, 2022
Use of hard-coded key in the BMC firmware for some Intel(R) Server Boards, Server Systems and...
Moderate
Unreviewed
CVE-2020-12376
was published
May 24, 2022
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of...
Moderate
Unreviewed
CVE-2021-26579
was published
May 24, 2022
In SOOIL Developments Co., Ltd Diabecare RS, AnyDana-i and AnyDana-A, a hard-coded physician PIN...
Moderate
Unreviewed
CVE-2020-27256
was published
May 24, 2022
A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a...
Moderate
Unreviewed
CVE-2021-3565
was published
May 24, 2022
An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel...
Moderate
Unreviewed
CVE-2020-25752
was published
May 24, 2022
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in...
Moderate
Unreviewed
CVE-2021-27481
was published
May 24, 2022
IBM Security Verify Access Docker 10.0.0 contains hard-coded credentials, such as a password or...
Moderate
Unreviewed
CVE-2021-20537
was published
May 24, 2022
Ypsomed mylife Cloud, mylife Mobile Application, Ypsomed mylife Cloud: All versions prior to 1.7...
Moderate
Unreviewed
CVE-2021-27503
was published
May 24, 2022
Use of a hard-coded cryptographic key in MIK.starlight 7.9.5.24363 allows local users to decrypt...
Moderate
Unreviewed
CVE-2021-36234
was published
May 24, 2022
Multiple Wireless M-Bus devices by Enbra use Hard-coded Credentials in Security mode 5 without an...
Moderate
Unreviewed
CVE-2021-34571
was published
May 24, 2022
A CWE-798: Use of Hardcoded Credentials vulnerability exists in Modicon Controllers (All versions...
Moderate
Unreviewed
CVE-2019-6859
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API