GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,335
Erlang
31
GitHub Actions
22
Go
2,096
Maven
5,000+
npm
3,762
NuGet
678
pip
3,448
Pub
12
RubyGems
892
Rust
882
Swift
37
Unreviewed advisories
All unreviewed
5,000+
474 advisories
Filter by severity
py-xml XML External Entity Injection vulnerability
High
CVE-2020-26709
was published
for
py-xml
(pip)
Jun 29, 2023
easy-parse XML External Entity Injection vulnerability
High
CVE-2020-26710
was published
for
easy-parse
(pip)
Jun 29, 2023
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common...
High
Unreviewed
CVE-2023-3113
was published
Jun 26, 2023
HuTool XML parsing module has blind XXE vulnerability
High
CVE-2023-3276
was published
for
cn.hutool:hutool-core
(Maven)
Jun 15, 2023
xml-rs vulnerable to denial of service via invalid token in XML document
High
CVE-2023-34411
was published
for
xml-rs
(Rust)
Jun 5, 2023
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks....
High
Unreviewed
CVE-2022-41221
was published
May 24, 2023
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE)....
High
Unreviewed
CVE-2023-27527
was published
May 10, 2023
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when...
High
Unreviewed
CVE-2023-28009
was published
Apr 26, 2023
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection ...
High
Unreviewed
CVE-2023-28008
was published
Apr 26, 2023
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing...
High
Unreviewed
CVE-2023-27876
was published
Apr 7, 2023
Jenkins Crap4J Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28680
was published
for
org.jenkins-ci.plugins:crap4j
(Maven)
Apr 2, 2023
Jenkins Visual Studio Code Metrics Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28681
was published
for
org.jenkins-ci.plugins:vs-code-metrics
(Maven)
Apr 2, 2023
Jenkins remote-jobs-view-plugin vulnerable to XML external entity attacks
High
CVE-2023-28684
was published
for
com.sap.jenkinsci:remote-jobs-view-plugin
(Maven)
Apr 2, 2023
Jenkins Performance Publisher Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28682
was published
for
org.jenkins-ci.plugins:perfpublisher
(Maven)
Apr 2, 2023
Jenkins Phabricator Differential Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28683
was published
for
org.jenkins-ci.plugins:phabricator-plugin
(Maven)
Apr 2, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2022-36969
was published
Mar 29, 2023
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when...
High
Unreviewed
CVE-2023-27874
was published
Mar 21, 2023
XWiki Platform vulnerable to data leak via Improper Restriction of XML External Entity Reference
High
CVE-2023-27480
was published
for
org.xwiki.platform:xwiki-platform-xar-model
(Maven)
Mar 8, 2023
OWSLib vulnerable to XML External Entity (XXE) Injection
High
CVE-2023-27476
was published
for
OWSLib
(pip)
Mar 7, 2023
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious...
High
Unreviewed
CVE-2023-20855
was published
Feb 22, 2023
dd-plist XML External Entitly vulnerability
High
CVE-2016-15026
was published
for
com.googlecode.plist:dd-plist
(Maven)
Feb 20, 2023
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the...
High
Unreviewed
CVE-2021-33950
was published
Feb 17, 2023
XML External Entity Reference in ureport
High
CVE-2023-24187
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 14, 2023
XML External Entity Reference in Apache NiFi
High
CVE-2023-22832
was published
for
org.apache.nifi:nifi-ccda-processors
(Maven)
Feb 10, 2023
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection...
High
Unreviewed
CVE-2023-24323
was published
Feb 9, 2023
ProTip!
Advisories are also available from the
GraphQL API