GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,314
Erlang
31
GitHub Actions
21
Go
2,072
Maven
5,000+
npm
3,744
NuGet
674
pip
3,433
Pub
12
RubyGems
892
Rust
880
Swift
37
Unreviewed advisories
All unreviewed
5,000+
382 advisories
Filter by severity
Malicious Package in bufger-xor
Critical
GHSA-2w8q-69fh-9gq6
was published
for
bufger-xor
(npm)
Sep 3, 2020
Malicious Package in jsmsha3
Critical
GHSA-657v-jjf8-83gh
was published
for
jsmsha3
(npm)
Sep 3, 2020
Malicious Package in bitcoimjs-lib
Critical
GHSA-rv6q-p3x7-43fx
was published
for
bitcoimjs-lib
(npm)
Sep 4, 2020
Malicious Package in bitcoijns-lib
Critical
GHSA-37vc-gwvp-6cgv
was published
for
bitcoijns-lib
(npm)
Sep 4, 2020
Malicious Package in bitcoin-osp
Critical
GHSA-v8g7-9qv2-j865
was published
for
bitcoin-osp
(npm)
Sep 4, 2020
Malicious Package in bitcoin-sweep
Critical
GHSA-8hqw-qp6r-vqcm
was published
for
bitcoin-sweep
(npm)
Sep 4, 2020
Malicious Package in sj-tw-sec
Critical
GHSA-692h-g37c-qv44
was published
for
sj-tw-sec
(npm)
Sep 3, 2020
Malicious Package in babel-laoder
Critical
GHSA-qp6m-jqfr-2f7v
was published
for
babel-laoder
(npm)
Sep 4, 2020
Malicious Package in bitcoimd-rpc
Critical
GHSA-rwmv-c7v8-v9vf
was published
for
bitcoimd-rpc
(npm)
Sep 4, 2020
Malicious Package in superhappyfuntime
Critical
GHSA-6qgx-f452-7699
was published
for
superhappyfuntime
(npm)
Sep 3, 2020
Malicious Package in babel-loadre
Critical
GHSA-vvfh-mvjv-w38q
was published
for
babel-loadre
(npm)
Sep 4, 2020
Malicious Package in crpyto-js
Critical
GHSA-73c6-vwjh-g3qh
was published
for
crpyto-js
(npm)
Sep 3, 2020
Malicious Package in hw-trnasport-u2f
Critical
GHSA-4363-x42f-xph6
was published
for
hw-trnasport-u2f
(npm)
Sep 3, 2020
Malicious Package in commandre
Critical
GHSA-r8hx-3qx6-hxq9
was published
for
commandre
(npm)
Sep 3, 2020
Malicious Package in riped160
Critical
GHSA-rwcq-qpm6-7867
was published
for
riped160
(npm)
Sep 3, 2020
Malicious Package in wallet-address-validtaor
Critical
GHSA-pc7q-c837-3wjq
was published
for
wallet-address-validtaor
(npm)
Sep 3, 2020
Malicious Package in bs58chcek
Critical
GHSA-97mp-9g5c-6c93
was published
for
bs58chcek
(npm)
Sep 4, 2020
Malicious Package in web3-eht
Critical
GHSA-29fh-xcjr-p7rx
was published
for
web3-eht
(npm)
Sep 3, 2020
Malicious npm package: an0n-chat-lib
Critical
GHSA-7xcv-wvr7-4h6p
was published
for
an0n-chat-lib
(npm)
Jan 29, 2021
Malicious Package in ripedm160
Critical
GHSA-9272-59x2-gwf2
was published
for
ripedm160
(npm)
Sep 3, 2020
Malicious Package in 1337qq-js
Critical
GHSA-7wgh-5q4q-6wx5
was published
for
1337qq-js
(npm)
Sep 4, 2020
Malicious code in `loadyaml`
Critical
GHSA-mfc2-93pr-jf92
was published
for
loadyaml
(npm)
Oct 1, 2020
Malicious npm package: discord-fix
Critical
GHSA-qv2g-99x4-45x6
was published
for
discord-fix
(npm)
Jan 29, 2021
Malicious npm package: sonatype
Critical
GHSA-w8fh-pvq2-x8c4
was published
for
sonatype
(npm)
Jan 29, 2021
ProTip!
Advisories are also available from the
GraphQL API