GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
73
GitHub Actions
53
Go
4,004
Maven
5,000+
npm
5,000+
NuGet
974
pip
5,000+
Pub
13
RubyGems
1,069
Rust
1,395
Swift
61
Unreviewed advisories
All unreviewed
5,000+
54 advisories
Filter by severity
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's...
Moderate
Unreviewed
CVE-2026-47325
was published
Jun 3, 2026
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not...
Moderate
Unreviewed
CVE-2026-4377
was published
May 28, 2026
In Slican telephone exchanges secure key is generated in a predictable manner using properties of...
High
Unreviewed
CVE-2026-35089
was published
May 27, 2026
ruby-jwt: Empty-key HMAC bypass; cross-language sibling of CVE-2026-44351
High
CVE-2026-45363
was published
for
jwt
(RubyGems)
May 18, 2026
slack-go `SecretsVerifier` accepts empty signing secret without precondition
Moderate
GHSA-gxhx-2686-5h9g
was published
for
github.com/slack-go/slack
(Go)
May 14, 2026
Weak credentials in the CashDro 3 web administration panel, version 24.01.00.26, where the...
Critical
Unreviewed
CVE-2026-8076
was published
May 8, 2026
fast-jwt: JWT auth bypass due to empty HMAC secret accepted by async key resolver
Critical
CVE-2026-44351
was published
for
fast-jwt
(npm)
May 6, 2026
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release...
High
Unreviewed
CVE-2026-23853
was published
Apr 17, 2026
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm...
Critical
Unreviewed
CVE-2025-67114
was published
Mar 19, 2026
OpenMQ exposes a TCP-based management service (imqbrokerd) that by default requires...
Critical
Unreviewed
CVE-2026-22886
was published
Mar 3, 2026
For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the...
Moderate
Unreviewed
CVE-2026-24449
was published
Feb 3, 2026
The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded...
Critical
Unreviewed
CVE-2025-59103
was published
Jan 26, 2026
The device's passwords have not been adequately salted, making them vulnerable to password...
Low
Unreviewed
CVE-2026-22920
was published
Jan 15, 2026
The device is deployed with weak and publicly known default passwords for certain hidden user...
High
Unreviewed
CVE-2026-22910
was published
Jan 15, 2026
The system is deployed in its default state, with configuration settings that do not comply with...
High
Unreviewed
CVE-2025-59460
was published
Oct 27, 2025
Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be...
Critical
Unreviewed
CVE-2025-30519
was published
Sep 18, 2025
Securden’s Unified PAM Remote Vendor Gateway access portal shares infrastructure and access...
High
Unreviewed
CVE-2025-6737
was published
Aug 26, 2025
TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain insecure credentials for the...
Moderate
Unreviewed
CVE-2025-55584
was published
Aug 18, 2025
On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password...
High
Unreviewed
CVE-2025-35970
was published
Aug 7, 2025
Partner Software's Partner Software Product and corresponding Partner Web application use the...
Critical
Unreviewed
CVE-2025-6077
was published
Aug 2, 2025
ZXHN-F660T and ZXHN-F660A provided by ZTE Japan K.K. use a common credential for all...
High
Unreviewed
CVE-2025-53558
was published
Jul 31, 2025
Use of weak credentials in emergency authentication component in Devolutions Server allows an...
High
Unreviewed
CVE-2025-6523
was published
Jul 22, 2025
Insecure Permissions vulnerability in Tenda CP3 Pro Firmware V22.5.4.93 allows the telnet service...
High
Unreviewed
CVE-2025-52364
was published
Jul 9, 2025
An unauthenticated attacker who knows the target device's serial number, can generate the default...
Critical
Unreviewed
CVE-2024-51978
was published
Jun 26, 2025
ActiveMQ Artemis AMQ Broker Operator Starting Credentials Reuse
Moderate
CVE-2025-4057
was published
for
github.com/arkmq-org/activemq-artemis-operator
(Go)
May 26, 2025
ProTip!
Advisories are also available from the
GraphQL API