GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,675
Maven
5,000+
npm
4,297
NuGet
760
pip
4,077
Pub
12
RubyGems
957
Rust
1,058
Swift
45
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
Apache Syncope can be configured to store the user password values in the internal database with...
High
Unreviewed
CVE-2025-65998
was published
Nov 24, 2025
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded...
High
Unreviewed
CVE-2025-13316
was published
Nov 19, 2025
A private key disclosure vulnerability exists in ZTE's ZXMP M721 product. A low-privileged user...
High
Unreviewed
CVE-2025-46582
was published
Oct 27, 2025
Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature...
High
Unreviewed
CVE-2025-34500
was published
Oct 25, 2025
Mojolicious versions from 0.999922 through 9.39 for Perl uses a hard coded string, or the...
High
Unreviewed
CVE-2024-58134
was published
May 3, 2025
Keysight Ixia Vision has an issue with hardcoded cryptographic material
which may allow an...
High
Unreviewed
CVE-2025-24525
was published
Oct 1, 2025
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported...
High
Unreviewed
CVE-2025-55112
was published
Sep 16, 2025
An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the...
High
Unreviewed
CVE-2025-56577
was published
Aug 29, 2025
Dell ECS versions prior to 3.8.1.5/ ObjectScale version 4.0.0.0, contain a Use of Hard-coded...
High
Unreviewed
CVE-2025-26476
was published
Aug 4, 2025
Dell Enterprise SONiC OS, version 4.5.0, contains a cryptographic key vulnerability in SSH. An...
High
Unreviewed
CVE-2025-38741
was published
Aug 4, 2025
Logsign Unified SecOps Platform HTTP API Hard-coded Cryptographic Key Remote Code Execution...
High
Unreviewed
CVE-2024-5722
was published
Nov 22, 2024
NetBird uses a static initialization vector (IV)
High
CVE-2024-41260
was published
for
github.com/netbirdio/netbird
(Go)
Aug 1, 2024
A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated...
High
Unreviewed
CVE-2025-22455
was published
Jun 10, 2025
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local...
High
Unreviewed
CVE-2025-22463
was published
Jun 10, 2025
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local...
High
Unreviewed
CVE-2025-5353
was published
Jun 10, 2025
itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient...
High
Unreviewed
CVE-2024-56429
was published
May 21, 2025
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a Hard-coded Password...
High
Unreviewed
CVE-2022-34462
was published
Jan 18, 2023
A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9...
High
Unreviewed
CVE-2017-6054
was published
May 13, 2022
Nexpose and InsightVM virtual appliances downloaded between April 5th, 2017 and May 3rd, 2017...
High
Unreviewed
CVE-2017-5242
was published
Jan 13, 2023
The Civi - Job Board & Freelance Marketplace WordPress Theme plugin for WordPress is vulnerable...
High
Unreviewed
CVE-2024-13773
was published
Mar 14, 2025
SmartOS, as used in Triton Data Center and other products, has static host SSH keys in the...
High
Unreviewed
CVE-2025-30234
was published
Mar 19, 2025
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and...
High
Unreviewed
CVE-2024-54027
was published
Mar 17, 2025
MGT-COMMERCE CloudPanel ships with a static SSL certificate to encrypt communications to the...
High
Unreviewed
CVE-2023-0391
was published
Mar 21, 2023
Delinea Secret Server before 11.7.000001 allows attackers to bypass authentication via the SOAP...
High
Unreviewed
CVE-2024-33891
was published
Apr 29, 2024
A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or...
High
Unreviewed
CVE-2025-26340
was published
Feb 12, 2025
ProTip!
Advisories are also available from the
GraphQL API