GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,850
Erlang
36
GitHub Actions
34
Go
2,480
Maven
5,000+
npm
4,097
NuGet
734
pip
3,910
Pub
12
RubyGems
945
Rust
1,014
Swift
39
Unreviewed advisories
All unreviewed
5,000+
38 advisories
Filter by severity
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access...
High
Unreviewed
CVE-2025-6737
was published
Aug 26, 2025
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the...
Moderate
Unreviewed
CVE-2025-55584
was published
Aug 18, 2025
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password...
High
Unreviewed
CVE-2025-35970
was published
Aug 7, 2025
Partner Software's Partner Software Product and corresponding Partner Web application use the...
Critical
Unreviewed
CVE-2025-6077
was published
Aug 2, 2025
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all...
High
Unreviewed
CVE-2025-53558
was published
Jul 31, 2025
Use of weak credentials in emergency authentication component in Devolutions Server allows an...
High
Unreviewed
CVE-2025-6523
was published
Jul 22, 2025
Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service...
High
Unreviewed
CVE-2025-52364
was published
Jul 9, 2025
An unauthenticated attacker who knows the target device's serial number, can generate the default...
Critical
Unreviewed
CVE-2024-51978
was published
Jun 26, 2025
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse
Moderate
CVE-2025-4057
was published
for
github.com/arkmq-org/activemq-artemis-operator
(Go)
May 26, 2025
The device’s passwords have not been adequately salted, making them vulnerable to password...
Low
Unreviewed
CVE-2025-32471
was published
Apr 28, 2025
A token is created using the username, current date/time, and a fixed
AES-128 encryption key,...
High
Unreviewed
CVE-2025-2229
was published
Mar 13, 2025
A vulnerability was found in Bharti Airtel Xstream Fiber up to 20250123. It has been rated as...
Low
Unreviewed
CVE-2025-1081
was published
Feb 6, 2025
An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W...
High
Unreviewed
CVE-2025-22936
was published
Feb 6, 2025
A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos...
Critical
Unreviewed
CVE-2024-12728
was published
Dec 19, 2024
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism...
High
Unreviewed
CVE-2024-45722
was published
Dec 6, 2024
Kieback & Peter's DDC4000 series uses weak credentials, which may allow an unauthenticated...
Critical
Unreviewed
CVE-2024-43698
was published
Oct 23, 2024
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the...
High
Unreviewed
CVE-2024-45272
was published
Oct 15, 2024
The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient,...
Moderate
Unreviewed
CVE-2024-42027
was published
Oct 7, 2024
JUJU_CONTEXT_ID is a predictable authentication secret
Moderate
CVE-2024-7558
was published
for
github.com/juju/juju
(Go)
Oct 3, 2024
Duplicate Advisory: Juju makes Use of Weak Credentials
High
GHSA-phh4-3hmm-24rx
was published
for
github.com/juju/juju
(Go)
Oct 2, 2024
•
withdrawn
A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This...
High
Unreviewed
CVE-2024-40892
was published
Aug 12, 2024
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with...
High
Unreviewed
CVE-2024-42051
was published
Jul 28, 2024
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
High
Unreviewed
CVE-2024-32759
was published
Jul 10, 2024
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet...
High
Unreviewed
CVE-2024-5634
was published
Jul 9, 2024
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
High
Unreviewed
CVE-2024-28066
was published
Apr 8, 2024
ProTip!
Advisories are also available from the
GraphQL API