GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,904
Erlang
38
GitHub Actions
38
Go
2,566
Maven
5,000+
npm
4,237
NuGet
753
pip
4,001
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
409 advisories
Filter by severity
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious...
Critical
Unreviewed
CVE-2018-25117
was published
Oct 15, 2025
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322,...
Critical
Unreviewed
CVE-2017-20203
was published
Oct 9, 2025
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and...
Critical
Unreviewed
CVE-2017-20202
was published
Oct 9, 2025
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry...
Critical
Unreviewed
CVE-2017-20201
was published
Oct 9, 2025
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322,...
Critical
Unreviewed
CVE-2025-34252
was published
Oct 7, 2025
TensorFlow v2.18.0 was discovered to output random results when compiling Embedding, leading to...
Moderate
Unreviewed
CVE-2025-55556
was published
Sep 25, 2025
Duplicate Advisory: Malicious versions of Nx were published
Critical
GHSA-8mjq-32x3-22qf
was published
for
nx
(npm)
Sep 25, 2025
•
withdrawn
[email protected] contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59143
was published
for
color
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59142
was published
for
color-string
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59141
was published
for
simple-swizzle
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59140
was published
for
backslash
(npm)
Sep 15, 2025
MetaMask SDK indirectly exposed via malicious [email protected] dependency
Moderate
GHSA-qj3p-xc97-xw74
was published
for
@metamask/sdk
(npm)
Sep 15, 2025
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
Prebid.js NPM package briefly compromised
High
CVE-2025-59038
was published
for
prebid.js
(npm)
Sep 11, 2025
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
High
CVE-2025-59037
was published
for
@duckdb/duckdb-wasm
(npm)
Sep 9, 2025
Malicious versions of Nx were published
Critical
CVE-2025-10894
was published
for
@nx/devkit
(npm)
Aug 27, 2025
num2words subjected to phishing attack, two versions published containing malware
Critical
GHSA-jxr6-qrxx-2ph2
was published
for
num2words
(pip)
Jul 31, 2025
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
High
CVE-2025-54313
was published
for
@pkgr/core
(npm)
Jul 19, 2025
Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
Critical
CVE-2025-32965
was published
for
xrpl
(npm)
Apr 22, 2025
Multiple Reviewdog actions were compromised during a specific time period
High
CVE-2025-30154
was published
for
reviewdog/action-setup
(GitHub Actions)
Mar 19, 2025
ProTip!
Advisories are also available from the
GraphQL API