Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

382 advisories

Loading
Shadowsock is malware Moderate
CVE-2017-16078 was published for shadowsock (npm) Aug 27, 2018
Malicious Package in eslint-scope Critical
GHSA-hxxf-q3w9-4xgw was published for eslint-config-eslint (npm) Jul 12, 2018
volkdm
Malware in pre-build binaries of bignum Critical
GHSA-7cgc-fjv4-52x6 was published for bignum (npm) May 24, 2023
calebbrown rvagg
Node.js bad High Unreviewed
CVE-2021-22884 was published May 24, 2022
Embedded Malicious Code in node-ipc Critical
CVE-2022-23812 was published for node-ipc (npm) Mar 16, 2022
Critical severity vulnerability that affects event-stream and flatmap-stream Critical
GHSA-mh6f-8j2x-4483 was published for event-stream (npm) Nov 26, 2018
Embedded malware in rc Critical
GHSA-g2q5-5433-rhrf was published for rc (npm) Nov 4, 2021
Embedded malware in coa Critical
GHSA-73qr-pfmq-6rp8 was published for coa (npm) Nov 4, 2021
Malicious npm package: discord-fix Critical
GHSA-qv2g-99x4-45x6 was published for discord-fix (npm) Jan 29, 2021
Malicious npm package: sonatype Critical
GHSA-w8fh-pvq2-x8c4 was published for sonatype (npm) Jan 29, 2021
Malicious code in `loadyaml` Critical
GHSA-mfc2-93pr-jf92 was published for loadyaml (npm) Oct 1, 2020
Malicious Package in 1337qq-js Critical
GHSA-7wgh-5q4q-6wx5 was published for 1337qq-js (npm) Sep 4, 2020
Malicious Package in bs58chcek Critical
GHSA-97mp-9g5c-6c93 was published for bs58chcek (npm) Sep 4, 2020
Malicious Package in commandre Critical
GHSA-r8hx-3qx6-hxq9 was published for commandre (npm) Sep 3, 2020
Malicious Package in crpyto-js Critical
GHSA-73c6-vwjh-g3qh was published for crpyto-js (npm) Sep 3, 2020
Malicious Package in hw-trnasport-u2f Critical
GHSA-4363-x42f-xph6 was published for hw-trnasport-u2f (npm) Sep 3, 2020
Malicious Package in ripedm160 Critical
GHSA-9272-59x2-gwf2 was published for ripedm160 (npm) Sep 3, 2020
Malicious Package in riped160 Critical
GHSA-rwcq-qpm6-7867 was published for riped160 (npm) Sep 3, 2020
Malicious Package in wallet-address-validtaor Critical
GHSA-pc7q-c837-3wjq was published for wallet-address-validtaor (npm) Sep 3, 2020
Malicious Package in web3-eht Critical
GHSA-29fh-xcjr-p7rx was published for web3-eht (npm) Sep 3, 2020
Malicious npm package: an0n-chat-lib Critical
GHSA-7xcv-wvr7-4h6p was published for an0n-chat-lib (npm) Jan 29, 2021
Malicious Package in sj-tw-sec Critical
GHSA-692h-g37c-qv44 was published for sj-tw-sec (npm) Sep 3, 2020
Malicious Package in superhappyfuntime Critical
GHSA-6qgx-f452-7699 was published for superhappyfuntime (npm) Sep 3, 2020
Malicious Package in babel-laoder Critical
GHSA-qp6m-jqfr-2f7v was published for babel-laoder (npm) Sep 4, 2020
Malicious Package in bitcoimjs-lib Critical
GHSA-rv6q-p3x7-43fx was published for bitcoimjs-lib (npm) Sep 4, 2020
ProTip! Advisories are also available from the GraphQL API