GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,237
Erlang
31
GitHub Actions
20
Go
2,000
Maven
5,000+
npm
3,711
NuGet
661
pip
3,383
Pub
11
RubyGems
885
Rust
849
Swift
36
Unreviewed advisories
All unreviewed
5,000+
311 advisories
Filter by severity
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML...
Moderate
Unreviewed
CVE-2016-9563
was published
Apr 30, 2022
In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling...
Moderate
Unreviewed
CVE-2022-2838
was published
Aug 17, 2022
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform...
Moderate
Unreviewed
CVE-2022-43570
was published
Nov 5, 2022
Jenkins RQM Plugin vulnerable to Improper Restriction of XML External Entity Reference
Moderate
CVE-2022-41241
was published
for
net.praqma:rqm-plugin
(Maven)
Sep 22, 2022
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
Moderate
Unreviewed
CVE-2020-24379
was published
May 24, 2022
XXE vulnerability on agents in Jenkins OSF Builder Suite : : XML Linter Plugin
Moderate
CVE-2022-45397
was published
for
org.jenkins-ci:update-center2
(Maven)
Nov 16, 2022
XXE vulnerability on agents in Jenkins SourceMonitor Plugin
Moderate
CVE-2022-45396
was published
for
com.thalesgroup.hudson.plugins:sourcemonitor
(Maven)
Nov 16, 2022
An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated...
Moderate
Unreviewed
CVE-2020-7032
was published
May 24, 2022
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references...
Moderate
Unreviewed
CVE-2022-1331
was published
May 4, 2022
Talend Administration Center has a vulnerability that allows an authenticated user to use XML...
Moderate
Unreviewed
CVE-2022-29943
was published
May 5, 2022
Apache NiFi information disclosure by XXE
Moderate
CVE-2019-10080
was published
for
org.apache.nifi:nifi
(Maven)
Dec 2, 2019
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x...
Moderate
Unreviewed
CVE-2017-8040
was published
May 13, 2022
XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote...
Moderate
Unreviewed
CVE-2018-10077
was published
May 13, 2022
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows...
Moderate
Unreviewed
CVE-2017-11457
was published
May 13, 2022
Concrete CMS vulnerable to XML External Entity
Moderate
CVE-2022-43689
was published
for
concrete5/concrete5
(Composer)
Nov 15, 2022
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML...
Moderate
Unreviewed
CVE-2016-3027
was published
May 13, 2022
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior...
Moderate
Unreviewed
CVE-2018-0207
was published
May 13, 2022
A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior...
Moderate
Unreviewed
CVE-2018-0218
was published
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache NiFi
Moderate
CVE-2020-13940
was published
for
org.apache.nifi:nifi
(Maven)
Jan 6, 2022
XML External Entity Reference in org.opencms:opencms-core
Moderate
CVE-2021-3312
was published
for
org.opencms:opencms-core
(Maven)
Oct 12, 2021
dbeaver is vulnerable to Improper Restriction of XML External Entity Reference
Moderate
Unreviewed
CVE-2021-3836
was published
Dec 15, 2021
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option...
Moderate
Unreviewed
CVE-2015-3451
was published
May 13, 2022
A vulnerability in the web-based user interface of Cisco Internet of Things Field Network...
Moderate
Unreviewed
CVE-2019-1698
was published
May 13, 2022
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External...
Moderate
Unreviewed
CVE-2022-40771
was published
Nov 23, 2022
External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows...
Moderate
Unreviewed
CVE-2018-6670
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API