GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,205
Erlang
31
GitHub Actions
19
Go
1,988
Maven
5,000+
npm
3,704
NuGet
661
pip
3,332
Pub
11
RubyGems
884
Rust
845
Swift
36
Unreviewed advisories
All unreviewed
5,000+
425 advisories
Filter by severity
An issue was discovered on FiberHome HG6245D devices through RP2613. The web management is done...
High
Unreviewed
CVE-2021-27142
was published
May 24, 2022
SolarWinds Orion Platform before 2020.2.4, as used by various SolarWinds products, installs and...
High
Unreviewed
CVE-2021-25275
was published
May 24, 2022
An issue was discovered on TK-Star Q90 Junior GPS horloge 3.1042.9.8656 devices. When using the...
High
Unreviewed
CVE-2019-20471
was published
May 24, 2022
Open5GS 2.1.3 listens on 0.0.0.0:3000 and has a default password of 1423 for the admin account.
High
Unreviewed
CVE-2021-25863
was published
May 24, 2022
An issue was discovered in Apexis Streaming Video Web Application on Geeni GNC-CW013 doorbell 1.8...
High
Unreviewed
CVE-2020-28999
was published
May 24, 2022
An attacker with local network access can obtain a fixed cryptography key which may allow for...
High
Unreviewed
CVE-2020-25173
was published
May 24, 2022
A vulnerability in Cisco Smart Software Manager Satellite could allow an authenticated, local...
High
Unreviewed
CVE-2021-1219
was published
May 24, 2022
A hard-coded password vulnerability has been reported to affect earlier versions of QES. If...
High
Unreviewed
CVE-2020-2499
was published
May 24, 2022
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by...
High
Unreviewed
CVE-2020-25620
was published
May 24, 2022
In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local...
High
Unreviewed
CVE-2020-0016
was published
May 24, 2022
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3)....
High
Unreviewed
CVE-2020-25229
was published
May 24, 2022
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1...
High
Unreviewed
CVE-2020-29375
was published
May 24, 2022
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600G1 V2.0.7 and V1.9.7, and...
High
Unreviewed
CVE-2020-29382
was published
May 24, 2022
An issue was discovered on V-SOL V1600D4L V1.01.49 and V1600D-MINI V1.01.48 OLT devices. A...
High
Unreviewed
CVE-2020-29383
was published
May 24, 2022
Airleader Master and Easy <= 6.21 devices have default credentials that can be used for a denial...
High
Unreviewed
CVE-2020-26509
was published
May 24, 2022
Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process)...
High
Unreviewed
CVE-2020-16258
was published
May 24, 2022
NVIDIA DGX servers, DGX-1 with BMC firmware versions prior to 3.38.30. DGX-2 with BMC firmware...
High
Unreviewed
CVE-2020-11487
was published
May 24, 2022
NVIDIA DGX servers, all BMC firmware versions prior to 3.38.30, contain a vulnerability in the...
High
Unreviewed
CVE-2020-11615
was published
May 24, 2022
Unisys Stealth(core) before 4.0.132 stores Passwords in a Recoverable Format.
High
Unreviewed
CVE-2020-24620
was published
May 24, 2022
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9...
High
Unreviewed
CVE-2018-17767
was published
May 24, 2022
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9...
High
Unreviewed
CVE-2018-17771
was published
May 24, 2022
GateManager versions prior to 9.2c, The affected product contains a hard-coded credential for...
High
Unreviewed
CVE-2020-14510
was published
May 24, 2022
The Temi application 1.3.3 through 1.3.7931 for Android has hard-coded credentials.
High
Unreviewed
CVE-2020-16170
was published
May 24, 2022
The GalaxyClientService component of GOG Galaxy runs with elevated SYSTEM privileges in a Windows...
High
Unreviewed
CVE-2020-7352
was published
May 24, 2022
An issue was discovered in MK-AUTH 19.01. There is authentication bypass in the web login...
High
Unreviewed
CVE-2020-14070
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API