Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

245 advisories

Loading
Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf Critical
CVE-2021-46849 was published for pikepdf (pip) Oct 24, 2022 withdrawn
Apache Calcite before 1.32.0 vulnerable to potential XML External Entity (XXE) attack Critical
CVE-2022-39135 was published for org.apache.calcite:calcite-core (Maven) Sep 12, 2022
Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2 Critical
CVE-2015-8031 was published for org.jvnet.hudson.main:hudson-core (Maven) Jul 15, 2022
Insufficient user input in Apache Jetspeed-2 Critical
CVE-2022-32533 was published for org.apache.portals.jetspeed-2:jetspeed-commons (Maven) Jul 7, 2022
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection... Critical Unreviewed
CVE-2022-23170 was published Jun 25, 2022
XML External Entity Reference in drools Critical
CVE-2021-41411 was published for org.drools:drools-core (Maven) Jun 17, 2022
wnicholson
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack. Critical Unreviewed
CVE-2021-45981 was published Jun 3, 2022
Improper Restriction of XML External Entity Reference in Stanford CoreNLP Critical
CVE-2021-3878 was published for edu.stanford.nlp:stanford-corenlp (Maven) May 24, 2022
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. Critical Unreviewed
CVE-2021-38298 was published May 24, 2022
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. Critical Unreviewed
CVE-2021-35066 was published May 24, 2022
XXE vulnerability in Jenkins Generic Webhook Trigger Plugin Critical
CVE-2021-21669 was published for org.jenkins-ci.plugins:generic-webhook-trigger (Maven) May 24, 2022
westonsteimel NotMyFault
ProTip! Advisories are also available from the GraphQL API