GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,198
Erlang
31
GitHub Actions
19
Go
1,986
Maven
5,000+
npm
3,702
NuGet
660
pip
3,328
Pub
11
RubyGems
883
Rust
843
Swift
36
Unreviewed advisories
All unreviewed
5,000+
245 advisories
Filter by severity
Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf
Critical
CVE-2021-46849
was published
for
pikepdf
(pip)
Oct 24, 2022
•
withdrawn
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The...
Critical
Unreviewed
CVE-2022-42307
was published
Oct 4, 2022
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine...
Critical
Unreviewed
CVE-2022-1700
was published
Sep 13, 2022
Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack
Critical
CVE-2022-39135
was published
for
org.apache.calcite:calcite-core
(Maven)
Sep 12, 2022
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity...
Critical
Unreviewed
CVE-2022-22489
was published
Aug 20, 2022
Due to an XML external entity reference, the software parses XML in the backup/restore...
Critical
Unreviewed
CVE-2022-1704
was published
Aug 6, 2022
IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4...
Critical
Unreviewed
CVE-2022-31775
was published
Aug 2, 2022
OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in...
Critical
Unreviewed
CVE-2022-2131
was published
Jul 26, 2022
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin...
Critical
Unreviewed
CVE-2022-35741
was published
Jul 19, 2022
Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2
Critical
CVE-2015-8031
was published
for
org.jvnet.hudson.main:hudson-core
(Maven)
Jul 15, 2022
Insufficient user input in Apache Jetspeed-2
Critical
CVE-2022-32533
was published
for
org.apache.portals.jetspeed-2:jetspeed-commons
(Maven)
Jul 7, 2022
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection...
Critical
Unreviewed
CVE-2022-23170
was published
Jun 25, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4...
Critical
Unreviewed
CVE-2021-45024
was published
Jun 18, 2022
XML External Entity Reference in drools
Critical
CVE-2021-41411
was published
for
org.drools:drools-core
(Maven)
Jun 17, 2022
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
Critical
Unreviewed
CVE-2021-45981
was published
Jun 3, 2022
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote...
Critical
Unreviewed
CVE-2021-34436
was published
May 24, 2022
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement...
Critical
Unreviewed
CVE-2020-25912
was published
May 24, 2022
Improper Restriction of XML External Entity Reference in Stanford CoreNLP
Critical
CVE-2021-3878
was published
for
edu.stanford.nlp:stanford-corenlp
(Maven)
May 24, 2022
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
Critical
Unreviewed
CVE-2021-38298
was published
May 24, 2022
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE)...
Critical
Unreviewed
CVE-2021-27741
was published
May 24, 2022
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file...
Critical
Unreviewed
CVE-2021-34823
was published
May 24, 2022
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes...
Critical
Unreviewed
CVE-2021-37425
was published
May 24, 2022
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External...
Critical
Unreviewed
CVE-2021-20399
was published
May 24, 2022
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Critical
Unreviewed
CVE-2021-35066
was published
May 24, 2022
XXE vulnerability in Jenkins Generic Webhook Trigger Plugin
Critical
CVE-2021-21669
was published
for
org.jenkins-ci.plugins:generic-webhook-trigger
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API