GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,395
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
387 advisories
Filter by severity
Malicious Package in @impala/bmap
Critical
GHSA-c82c-8pjw-6829
was published
for
@impala/bmap
(npm)
Sep 1, 2020
Malicious Package in another-date-range-picker
Critical
GHSA-8rxg-9g6f-vq9p
was published
for
another-date-range-picker
(npm)
Sep 1, 2020
Malicious Package in beffer-xor
Critical
GHSA-7cvf-p83w-48q6
was published
for
beffer-xor
(npm)
Sep 3, 2020
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The...
Critical
Unreviewed
CVE-2024-3094
was published
Mar 29, 2024
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4...
Critical
Unreviewed
CVE-2023-2003
was published
Jul 13, 2023
Withdrawn Advisory: mariadb was malware
High
CVE-2017-16046
was published
for
mariadb
(npm)
Jul 18, 2018
•
withdrawn
Justice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is...
High
Unreviewed
CVE-2024-4978
was published
May 23, 2024
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
High
CVE-2025-30066
was published
for
tj-actions/changed-files
(GitHub Actions)
Mar 15, 2025
Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
Critical
CVE-2025-32965
was published
for
xrpl
(npm)
Apr 22, 2025
Multiple Reviewdog actions were compromised during a specific time period
High
CVE-2025-30154
was published
for
reviewdog/action-setup
(GitHub Actions)
Mar 19, 2025
eslint-config-prettier, eslint-plugin-prettier, synckit, @pkgr/core, napi-postinstall have embedded malicious code
High
CVE-2025-54313
was published
for
@pkgr/core
(npm)
Jul 19, 2025
ProTip!
Advisories are also available from the
GraphQL API