Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

336 advisories

Loading
Prebid-universal-creative latest on npm briefly compromised Critical
CVE-2025-59039 was published for prebid-universal-creative (npm) Sep 11, 2025
Malicious versions of Nx were published Critical
GHSA-cxm3-wv7p-598c was published for @nx/devkit (npm) Aug 27, 2025
jahredhope tadhglewis
hckhanh TimShilov
Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2 Critical
CVE-2025-32965 was published for xrpl (npm) Apr 22, 2025
Malicious Package in beffer-xor Critical
GHSA-7cvf-p83w-48q6 was published for beffer-xor (npm) Sep 3, 2020
mprpic
Malicious Package in another-date-range-picker Critical
GHSA-8rxg-9g6f-vq9p was published for another-date-range-picker (npm) Sep 1, 2020
Malicious Package in @impala/bmap Critical
GHSA-c82c-8pjw-6829 was published for @impala/bmap (npm) Sep 1, 2020
Malicious Package in another-date-picker Critical
GHSA-2p62-c4rm-mr72 was published for another-date-picker (npm) Sep 1, 2020
mprpic
npm-script-demo is malware Critical
CVE-2017-16128 was published for npm-script-demo (npm) Sep 1, 2020
Malicious Package in eslint-scope Critical
GHSA-hxxf-q3w9-4xgw was published for eslint-config-eslint (npm) Jul 12, 2018
volkdm
Malware in pre-build binaries of bignum Critical
GHSA-7cgc-fjv4-52x6 was published for bignum (npm) May 24, 2023
calebbrown rvagg
Embedded Malicious Code in node-ipc Critical
CVE-2022-23812 was published for node-ipc (npm) Mar 16, 2022
Embedded malware in rc Critical
GHSA-g2q5-5433-rhrf was published for rc (npm) Nov 4, 2021
Critical severity vulnerability that affects event-stream and flatmap-stream Critical
GHSA-mh6f-8j2x-4483 was published for event-stream (npm) Nov 26, 2018
Embedded malware in coa Critical
GHSA-73qr-pfmq-6rp8 was published for coa (npm) Nov 4, 2021
Malicious npm package: sonatype Critical
GHSA-w8fh-pvq2-x8c4 was published for sonatype (npm) Jan 29, 2021
Malicious npm package: discord-fix Critical
GHSA-qv2g-99x4-45x6 was published for discord-fix (npm) Jan 29, 2021
Malicious code in `loadyaml` Critical
GHSA-mfc2-93pr-jf92 was published for loadyaml (npm) Oct 1, 2020
Malicious Package in 1337qq-js Critical
GHSA-7wgh-5q4q-6wx5 was published for 1337qq-js (npm) Sep 4, 2020
Malicious Package in crpyto-js Critical
GHSA-73c6-vwjh-g3qh was published for crpyto-js (npm) Sep 3, 2020
Malicious Package in commandre Critical
GHSA-r8hx-3qx6-hxq9 was published for commandre (npm) Sep 3, 2020
Malicious Package in wallet-address-validtaor Critical
GHSA-pc7q-c837-3wjq was published for wallet-address-validtaor (npm) Sep 3, 2020
Malicious Package in bs58chcek Critical
GHSA-97mp-9g5c-6c93 was published for bs58chcek (npm) Sep 4, 2020
Malicious Package in hw-trnasport-u2f Critical
GHSA-4363-x42f-xph6 was published for hw-trnasport-u2f (npm) Sep 3, 2020
Malicious Package in ripedm160 Critical
GHSA-9272-59x2-gwf2 was published for ripedm160 (npm) Sep 3, 2020
Malicious Package in web3-eht Critical
GHSA-29fh-xcjr-p7rx was published for web3-eht (npm) Sep 3, 2020
ProTip! Advisories are also available from the GraphQL API