GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,870
Erlang
37
GitHub Actions
36
Go
2,500
Maven
5,000+
npm
4,147
NuGet
735
pip
3,948
Pub
12
RubyGems
945
Rust
1,025
Swift
39
Unreviewed advisories
All unreviewed
5,000+
52 advisories
Filter by severity
[email protected] contains malware after npm account takeover
High
CVE-2025-59331
was published
for
is-arrayish
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59330
was published
for
error-ex
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59162
was published
for
color-convert
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59145
was published
for
color-name
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59144
was published
for
debug
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59143
was published
for
color
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59142
was published
for
color-string
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59141
was published
for
simple-swizzle
(npm)
Sep 15, 2025
[email protected] contains malware after npm account takeover
High
CVE-2025-59140
was published
for
backslash
(npm)
Sep 15, 2025
Prebid.js NPM package briefly compromised
High
CVE-2025-59038
was published
for
prebid.js
(npm)
Sep 11, 2025
DuckDB NPM packages 1.3.3 and 1.29.2 briefly compromised with malware
High
CVE-2025-59037
was published
for
@duckdb/duckdb-wasm
(npm)
Sep 9, 2025
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
High
CVE-2025-54313
was published
for
@pkgr/core
(npm)
Jul 19, 2025
Multiple Reviewdog actions were compromised during a specific time period
High
CVE-2025-30154
was published
for
reviewdog/action-setup
(GitHub Actions)
Mar 19, 2025
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
High
CVE-2025-30066
was published
for
tj-actions/changed-files
(GitHub Actions)
Mar 15, 2025
Entropy Backdoor in text-qrcode
High
GHSA-h5vj-f7r9-w564
was published
for
text-qrcode
(npm)
Sep 1, 2020
ProTip!
Advisories are also available from the
GraphQL API