All CVEs (52)
CVE-2024-3094
CRITICALMalicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a di...
CVE-2023-2003
CRITICALEmbedded malicious code vulnerability in Vision1210, in the build 5 of operating system version 4.3, which could allow a remote attacker to store base64-encoded malicious code in the device's data tab...
CVE-2017-16128
CRITICALThe module npm-script-demo opened a connection to a command and control server. It has been removed from the npm registry.
CVE-2020-15165
CRITICALVersion 1.1.6-free of Chameleon Mini Live Debugger on Google Play Store may have had it's sources or permissions tampered by a malicious actor. The official maintainer of the package is recommending a...
CVE-2025-30154
HIGHreviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed s...
CVE-2025-30066
HIGHtj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modifi...
CVE-2024-4978
HIGHJustice AV Solutions Viewer Setup 8.3.7.250-1 contains a malicious binary when executed and is signed with an unexpected authenticode signature. A remote, privileged threat actor may exploit this vuln...
CVE-2017-16205
HIGHThe coffescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16204
HIGHThe jquey module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16203
HIGHThe coffe-script module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16202
HIGHThe cofeescript module exfiltrates sensitive data such as a user's private SSH key and bash history to a third party server during installation.
CVE-2017-16081
HIGHcross-env.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16080
HIGHnodesass was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16079
HIGHsmb was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16078
HIGHshadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16077
HIGHmongose was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16076
HIGHproxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16075
HIGHhttp-proxy.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16074
HIGHcrossenv was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16073
HIGHnoderequest was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16072
HIGHnodemailer.js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16071
HIGHnodemailer-js was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16070
HIGHnodecaffe was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
CVE-2017-16069
HIGHnodeffmpeg was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.