GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,333
Erlang
31
GitHub Actions
21
Go
2,094
Maven
5,000+
npm
3,759
NuGet
678
pip
3,445
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
1,058 advisories
Filter by severity
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML...
Low
Unreviewed
CVE-2024-42185
was published
Jan 23, 2025
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML...
Moderate
Unreviewed
CVE-2016-9563
was published
Apr 30, 2022
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
project, allowing an...
High
Unreviewed
CVE-2025-23195
was published
Jan 22, 2025
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of...
Moderate
Unreviewed
CVE-2018-9379
was published
Jan 18, 2025
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete...
High
Unreviewed
CVE-2018-9375
was published
Jan 18, 2025
Improper Restriction of XML External Entity Reference in Mulesoft APIkit
Critical
CVE-2020-10991
was published
for
org.mule.modules:mule-apikit-module
(Maven)
May 24, 2022
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could...
High
Unreviewed
CVE-2024-12476
was published
Jan 17, 2025
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB...
Moderate
Unreviewed
CVE-2024-12298
was published
Jan 14, 2025
veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
Low
CVE-2024-52800
was published
for
org.verapdf:core
(Maven)
Dec 2, 2024
An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML...
High
Unreviewed
CVE-2024-46602
was published
Jan 7, 2025
xml-rs vulnerable to denial of service via invalid token in XML document
High
CVE-2023-34411
was published
for
xml-rs
(Rust)
Jun 5, 2023
An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder...
High
Unreviewed
CVE-2024-46603
was published
Jan 7, 2025
An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB...
Critical
Unreviewed
CVE-2024-55081
was published
Dec 19, 2024
In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can...
Critical
Unreviewed
CVE-2024-40896
was published
Dec 23, 2024
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE...
Moderate
Unreviewed
CVE-2024-56356
was published
Dec 20, 2024
Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations...
Moderate
Unreviewed
CVE-2021-22501
was published
Dec 19, 2024
SimpleSAMLphp SAML2 has an XXE in parsing SAML messages
Moderate
CVE-2024-52806
was published
for
simplesamlphp/saml2
(Composer)
Dec 2, 2024
Ucum-java has an XXE vulnerability in XML parsing
High
CVE-2024-55887
was published
for
org.fhir:ucum
(Maven)
Dec 13, 2024
http4k has a potential XXE (XML External Entity Injection) vulnerability
Critical
CVE-2024-55875
was published
for
org.http4k:http4k-format-xml
(Maven)
Dec 12, 2024
SimpleSAMLphp xml-common XXE vulnerability
High
CVE-2024-52596
was published
for
simplesamlphp/xml-common
(Composer)
Dec 2, 2024
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow...
High
Unreviewed
CVE-2024-53675
was published
Nov 27, 2024
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow...
High
Unreviewed
CVE-2024-53674
was published
Nov 27, 2024
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow...
High
Unreviewed
CVE-2024-11622
was published
Nov 27, 2024
Microsoft SharePoint Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49064
was published
Dec 12, 2024
Liferay Portal has an XXE vulnerability in Java2WsddTask._format
High
CVE-2024-25606
was published
for
com.liferay.portal:com.liferay.util.java
(Maven)
Feb 20, 2024
ProTip!
Advisories are also available from the
GraphQL API