Search across all tracked vulnerability databases
Browse and filter security vulnerabilities across ecosystems
j178/prek-action vulnerable to arbitrary code injection in composite action
CVE-2025-59844
Argument injection vulnerability in SonarQube Scan Action
PyPI publish GitHub Action vulnerable to injectable expression expansions in action steps
CVE-2025-58178
Command Injection via sonarqube-scan-action GitHub Action
CVE-2024-48908
lychee link checking action affected by arbitrary code injection in composite action
m00nl1ght-dev/steam-workshop-deploy: Exposure of Version-Control Repository to an Unauthorized Control Sphere and Insufficiently Protected Credentials
CVE-2025-54416
tj-actions/branch-names has a Command Injection Vulnerability
RageAgainstThePixel/setup-steamcmd leaked authentication token in job output logs
buildalon/setup-steamcmd leaked authentication token in job output logs
Cromwell GitHub Actions Secrets exfiltration via `Issue_comment`
CVE-2025-47775
Bullfrog's DNS over TCP bypasses domain filtering
CVE-2025-47271
OZI-Project/ozi-publish Code Injection vulnerability
CVE-2025-32955
Harden-Runner allows evasion of 'disable-sudo' policy
CVE-2025-31479
canonical/get-workflow-version-action can leak a partial GITHUB_TOKEN in exception output
CVE-2025-30154
Multiple Reviewdog actions were compromised during a specific time period
CVE-2025-30066
tj-actions changed-files through 45.0.7 allows remote attackers to discover secrets by reading actions logs.
CVE-2025-24362
GitHub PAT written to debug artifacts
Artifact poisoning vulnerability in action-download-artifact v5 and earlier
CVE-2024-52587
Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`
@actions/download-artifact has an Arbitrary File Write via artifact extraction
Showing 1 - 20 of 1,000+ results