GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,856
Erlang
36
GitHub Actions
36
Go
2,488
Maven
5,000+
npm
4,104
NuGet
735
pip
3,923
Pub
12
RubyGems
945
Rust
1,017
Swift
39
Unreviewed advisories
All unreviewed
5,000+
Unreviewed advisories have not been assessed by GitHub for quality and do not connect to the Dependabot service.
17 advisories
Filter by severity
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access...
High
Unreviewed
CVE-2025-6737
was published
Aug 26, 2025
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password...
High
Unreviewed
CVE-2025-35970
was published
Aug 7, 2025
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all...
High
Unreviewed
CVE-2025-53558
was published
Jul 31, 2025
Use of weak credentials in emergency authentication component in Devolutions Server allows an...
High
Unreviewed
CVE-2025-6523
was published
Jul 22, 2025
Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service...
High
Unreviewed
CVE-2025-52364
was published
Jul 9, 2025
A token is created using the username, current date/time, and a fixed
AES-128 encryption key,...
High
Unreviewed
CVE-2025-2229
was published
Mar 13, 2025
An issue in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi router SAM-4G1G-TT-W-VC, SAM-4F1F-TT-W...
High
Unreviewed
CVE-2025-22936
was published
Feb 6, 2025
Ruijie Reyee OS versions 2.206.x up to but not including 2.320.x uses weak credential mechanism...
High
Unreviewed
CVE-2024-45722
was published
Dec 6, 2024
An unauthenticated remote attacker can perform a brute-force attack on the credentials of the...
High
Unreviewed
CVE-2024-45272
was published
Oct 15, 2024
A weak credential vulnerability exists in Firewalla Box Software versions before 1.979. This...
High
Unreviewed
CVE-2024-40892
was published
Aug 12, 2024
The MSI installer for Splashtop Streamer for Windows before 3.6.2.0 uses a temporary folder with...
High
Unreviewed
CVE-2024-42051
was published
Jul 28, 2024
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
High
Unreviewed
CVE-2024-32759
was published
Jul 10, 2024
Longse model LBH30FE200W cameras, as well as products based on this device, make use of telnet...
High
Unreviewed
CVE-2024-5634
was published
Jul 9, 2024
In Unify CP IP Phone firmware 1.10.4.3, Weak Credentials are used (a hardcoded root password).
High
Unreviewed
CVE-2024-28066
was published
Apr 8, 2024
HGW BL1500HM Ver 002.001.013 and earlier contains a use of week credentials issue. A network...
High
Unreviewed
CVE-2024-29071
was published
Mar 25, 2024
The vulnerability allows a remote attacker to access sensitive data inside exported packages or...
High
Unreviewed
CVE-2023-48257
was published
Jan 10, 2024
The Priva TopControl Suite contains predictable credentials for the SSH service, based on the...
High
Unreviewed
CVE-2022-3010
was published
Jan 2, 2024
ProTip!
Advisories are also available from the
GraphQL API