GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
44
GitHub Actions
45
Go
3,248
Maven
5,000+
npm
5,000+
NuGet
867
pip
4,513
Pub
12
RubyGems
997
Rust
1,189
Swift
51
Unreviewed advisories
All unreviewed
5,000+
352 advisories
Filter by severity
xygeni-action v5 tag poisoned with C2 backdoor
Critical
CVE-2026-31976
was published
for
xygeni/xygeni-action
(GitHub Actions)
Mar 11, 2026
`polymarket-client-sdks` was removed from crates.io for malicious code
Critical
GHSA-p5vf-5754-x7p3
was published
for
polymarket-client-sdks
(Rust)
Feb 13, 2026
`sha-rst` was removed from crates.io for malicious code
Critical
GHSA-vgr2-r5hm-f6gf
was published
for
sha-rst
(Rust)
Feb 12, 2026
`finch_cli_rust` was removed from crates.io for malicious code
Critical
GHSA-6v2j-vr4h-f632
was published
for
finch_cli_rust
(Rust)
Feb 12, 2026
`finch-rst` was removed from crates.io for malicious code
Critical
GHSA-xp79-9mxw-878j
was published
for
finch-rst
(Rust)
Feb 12, 2026
A single post-release of dydx-v4-client contained obfuscated multi-stage loader
Critical
GHSA-4f84-67cv-qrv3
was published
for
dydx-v4-client
(pip)
Feb 6, 2026
"UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with...
Critical
Unreviewed
CVE-2025-59374
was published
Dec 17, 2025
VestaCP commit a3f0fa1 (2018-05-31) up to commit ee03eff (2018-06-13) contain embedded malicious...
Critical
Unreviewed
CVE-2018-25117
was published
Oct 15, 2025
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322,...
Critical
Unreviewed
CVE-2017-20203
was published
Oct 9, 2025
Web Developer for Chrome v0.4.9 contained malicious code that generated a domain via a DGA and...
Critical
Unreviewed
CVE-2017-20202
was published
Oct 9, 2025
CCleaner v5.33.6162 and CCleaner Cloud v1.07.3191 (32-bit builds) contained a malicious pre-entry...
Critical
Unreviewed
CVE-2017-20201
was published
Oct 9, 2025
NetSarang Xmanager Enterprise 5.0 Build 1232, Xmanager 5.0 Build 1045, Xshell 5.0 Build 1322,...
Critical
Unreviewed
CVE-2025-34252
was published
Oct 7, 2025
Malicious versions of Nx were published
Critical
CVE-2025-10894
was published
for
@nx/devkit
(npm)
Aug 27, 2025
Duplicate Advisory: Malicious versions of Nx were published
Critical
GHSA-8mjq-32x3-22qf
was published
for
nx
(npm)
Sep 25, 2025
•
withdrawn
Prebid-universal-creative latest on npm briefly compromised
Critical
CVE-2025-59039
was published
for
prebid-universal-creative
(npm)
Sep 11, 2025
num2words subjected to phishing attack, two versions published containing malware
Critical
GHSA-jxr6-qrxx-2ph2
was published
for
num2words
(pip)
Jul 31, 2025
Compromised xrpl.js versions 4.2.1, 4.2.2, 4.2.3, 4.2.4, and 2.14.2
Critical
CVE-2025-32965
was published
for
xrpl
(npm)
Apr 22, 2025
Embedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4...
Critical
Unreviewed
CVE-2023-2003
was published
Jul 13, 2023
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. The...
Critical
Unreviewed
CVE-2024-3094
was published
Mar 29, 2024
Malicious Package in beffer-xor
Critical
GHSA-7cvf-p83w-48q6
was published
for
beffer-xor
(npm)
Sep 3, 2020
Malicious Package in another-date-range-picker
Critical
GHSA-8rxg-9g6f-vq9p
was published
for
another-date-range-picker
(npm)
Sep 1, 2020
Malicious Package in @impala/bmap
Critical
GHSA-c82c-8pjw-6829
was published
for
@impala/bmap
(npm)
Sep 1, 2020
Malicious Package in another-date-picker
Critical
GHSA-2p62-c4rm-mr72
was published
for
another-date-picker
(npm)
Sep 1, 2020
npm-script-demo is malware
Critical
CVE-2017-16128
was published
for
npm-script-demo
(npm)
Sep 1, 2020
Malicious Package in eslint-scope
Critical
GHSA-hxxf-q3w9-4xgw
was published
for
eslint-config-eslint
(npm)
Jul 12, 2018
ProTip!
Advisories are also available from the
GraphQL API