Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

52 advisories

Loading
[email protected] contains malware after npm account takeover High
CVE-2025-59331 was published for is-arrayish (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59330 was published for error-ex (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59162 was published for color-convert (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59145 was published for color-name (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59144 was published for debug (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59143 was published for color (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59142 was published for color-string (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59141 was published for simple-swizzle (npm) Sep 15, 2025
[email protected] contains malware after npm account takeover High
CVE-2025-59140 was published for backslash (npm) Sep 15, 2025
Prebid.js NPM package briefly compromised High
CVE-2025-59038 was published for prebid.js (npm) Sep 11, 2025
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware High
CVE-2025-59037 was published for @duckdb/duckdb-wasm (npm) Sep 9, 2025
Multiple Reviewdog actions were compromised during a specific time period High
CVE-2025-30154 was published for reviewdog/action-setup (GitHub Actions) Mar 19, 2025
sshayb ramimac
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs. High
CVE-2025-30066 was published for tj-actions/changed-files (GitHub Actions) Mar 15, 2025
varunsh-coder
Entropy Backdoor in text-qrcode High
GHSA-h5vj-f7r9-w564 was published for text-qrcode (npm) Sep 1, 2020
mysqljs is malware High
CVE-2017-16047 was published for mysqljs (npm) Sep 1, 2020
lodahs is malware High
CVE-2019-19771 was published for lodahs (npm) Dec 16, 2019
sqlserver is malware High
CVE-2017-16055 was published for sqlserver (npm) Nov 9, 2018
gruntcli is malware High
CVE-2017-16058 was published for gruntcli (npm) Nov 9, 2018
mssql-node is malware High
CVE-2017-16059 was published for mssql-node (npm) Nov 9, 2018
mssql.js is malware High
CVE-2017-16056 was published for mssql.js (npm) Nov 9, 2018
nodemssql is malware High
CVE-2017-16057 was published for nodemssql (npm) Nov 9, 2018
node-tkinter is malware High
CVE-2017-16062 was published for node-tkinter (npm) Nov 1, 2018
tkinter is malware High
CVE-2017-16061 was published for tkinter (npm) Nov 1, 2018
mongose is malware High
CVE-2017-16077 was published for mongose (npm) Oct 10, 2018
ProTip! Advisories are also available from the GraphQL API