GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
43 advisories
Filter by severity
The default configuration of WatchGuard Firebox devices through 2025-09-10 allows administrative...
Critical
Unreviewed
CVE-2025-59396
was published
Nov 6, 2025
The affected devices use publicly available default credentials with administrative privileges.
Critical
Unreviewed
CVE-2023-39169
was published
Dec 7, 2023
Authentication bypass in Apache Airflow
Critical
CVE-2020-13927
was published
for
apache-airflow
(pip)
Apr 30, 2021
Unitronics Vision Series PLCs and HMIs use default administrative passwords. An unauthenticated...
Critical
Unreviewed
CVE-2023-6448
was published
Dec 5, 2023
In Apache CouchDB prior to 3.2.2, an attacker can access an improperly secured default...
Critical
Unreviewed
CVE-2022-24706
was published
Apr 27, 2022
The HEIDENHAIN Controller TNC 640, version 340590 07 SP5, running HEROS 5.08.3 controlling the...
Critical
Unreviewed
CVE-2022-41648
was published
Oct 28, 2022
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation...
Critical
Unreviewed
CVE-2025-7353
was published
Aug 14, 2025
NodeJS version of HAX CMS Has Insecure Default Configuration That Leads to Unauthenticated Access
Critical
CVE-2025-54127
was published
for
@haxtheweb/haxcms-nodejs
(npm)
Jul 21, 2025
A remote unauthenticated attacker may use default certificates to generate JWT Tokens and gain...
Critical
Unreviewed
CVE-2025-41672
was published
Jul 7, 2025
The Versa Director software exposes a number of services by default and allow attackers an easy...
Critical
Unreviewed
CVE-2025-24288
was published
Jun 19, 2025
The CS5000 Fire Panel is vulnerable due to a default account that exists
on the panel. Even...
Critical
Unreviewed
CVE-2025-41438
was published
May 30, 2025
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in...
Critical
Unreviewed
CVE-2017-5178
was published
May 13, 2022
Insecure default settings have been found in recorder products provided by Yokogawa Electric...
Critical
Unreviewed
CVE-2025-1863
was published
Apr 18, 2025
CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could...
Critical
Unreviewed
CVE-2025-1960
was published
Mar 12, 2025
Liferay Portal has a Stored XSS with Blog entries (Insecure defaults)
Critical
CVE-2024-25610
was published
for
com.liferay.portal:com.liferay.portal.web
(Maven)
Feb 20, 2024
A condition exists in FlashArray Purity whereby a local account intended for initial array...
Critical
Unreviewed
CVE-2024-0001
was published
Sep 23, 2024
Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR...
Critical
Unreviewed
CVE-2024-31070
was published
Jul 17, 2024
A vulnerability in the BluStar component of Mitel InAttend 2.6 SP4 through 2.7 and CMG 8.5 SP4...
Critical
Unreviewed
CVE-2024-28815
was published
Mar 27, 2024
Insecure deserialization in BentoML
Critical
CVE-2024-2912
was published
for
bentoml
(pip)
Apr 16, 2024
NetApp AFF A700s Baseboard Management Controller (BMC) firmware versions 1.22 and higher were...
Critical
Unreviewed
CVE-2019-5497
was published
May 24, 2022
doorGets 7.0 has a default administrator credential vulnerability. A remote attacker can use this...
Critical
Unreviewed
CVE-2019-11618
was published
May 24, 2022
The defaults settings for the CORS filter provided in Apache Tomcat are insecure and enable 'supportsCredentials' for all origins
Critical
CVE-2018-8014
was published
for
org.apache.tomcat.embed:tomcat-embed-core
(Maven)
Oct 17, 2018
In JetBrains TeamCity before 2022.10.2 jVMTI was enabled by default on agents.
Critical
Unreviewed
CVE-2022-48342
was published
Feb 23, 2023
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC...
Critical
Unreviewed
CVE-2019-4169
was published
May 24, 2022
An issue was discovered on Tenda AC15 devices. A remote, unauthenticated attacker can make a...
Critical
Unreviewed
CVE-2018-5770
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API