GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,871
Erlang
37
GitHub Actions
36
Go
2,517
Maven
5,000+
npm
4,154
NuGet
736
pip
3,953
Pub
12
RubyGems
946
Rust
1,026
Swift
39
Unreviewed advisories
All unreviewed
5,000+
1,143 advisories
Filter by severity
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references...
Moderate
Unreviewed
CVE-2022-1331
was published
May 4, 2022
The XSL stylesheet implementation in WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2...
High
Unreviewed
CVE-2009-1699
was published
May 2, 2022
The Adobe Reader control in Adobe Reader and Acrobat 7.0 and 7.0.1 allows remote attackers to...
Moderate
Unreviewed
CVE-2005-1306
was published
May 1, 2022
Multiple components in Apache NiFi do not restrict XML External Entity references
High
CVE-2022-29265
was published
for
org.apache.nifi:nifi
(Maven)
May 1, 2022
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML...
Moderate
Unreviewed
CVE-2016-9563
was published
Apr 30, 2022
Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF...
Critical
Unreviewed
CVE-2022-24449
was published
Apr 29, 2022
Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml
Moderate
CVE-2022-24898
was published
for
org.xwiki.commons:xwiki-commons-xml
(Maven)
Apr 28, 2022
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external...
High
Unreviewed
CVE-2012-1102
was published
Apr 23, 2022
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External...
High
Unreviewed
CVE-2011-3600
was published
Apr 22, 2022
XML External Entity Reference in detekt
High
CVE-2022-0272
was published
for
io.gitlab.arturbosch.detekt:detekt-core
(Maven)
Apr 22, 2022
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted...
Moderate
Unreviewed
CVE-2021-43990
was published
Apr 21, 2022
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could...
Moderate
Unreviewed
CVE-2022-0221
was published
Apr 14, 2022
Inline DTD allows XML bomb attack
High
CVE-2019-15160
was published
for
sweet_xml
(Erlang)
Apr 12, 2022
Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that...
Critical
Unreviewed
CVE-2022-28219
was published
Apr 6, 2022
When opening a malicious solution file provided by an attacker, the application suffers from an...
Moderate
Unreviewed
CVE-2022-1018
was published
Apr 3, 2022
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA...
High
Unreviewed
CVE-2021-33208
was published
Apr 1, 2022
Improper Restriction of XML External Entity Reference in wutka jox
Moderate
CVE-2021-43142
was published
for
com.wutka:jox
(Maven)
Apr 1, 2022
XML External Entity Reference vulnerability in Jenkins Pipeline: Phoenix AutoTest Plugin
High
CVE-2022-28155
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
XXE vulnerability in Jenkins Flaky Test Handler Plugin
High
CVE-2022-28140
was published
for
org.jenkins-ci.plugins:flaky-test-handler
(Maven)
Mar 30, 2022
enkins Coverage/Complexity Scatter Plot Plugin XML External Entity Reference vulnerability
High
CVE-2022-28154
was published
for
org.jenkins-ci.plugins:covcomplplot
(Maven)
Mar 30, 2022
Improper Restriction of XML External Entity Reference in soa-model
Critical
CVE-2021-43090
was published
for
com.predic8:soa-model-core
(Maven)
Mar 26, 2022
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability...
High
Unreviewed
CVE-2021-44477
was published
Mar 26, 2022
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10...
Moderate
Unreviewed
CVE-2022-0861
was published
Mar 24, 2022
The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's...
High
Unreviewed
CVE-2021-42194
was published
Mar 22, 2022
XML external entity (XXE) attacks in Jenkins Xcode integration Plugin
High
CVE-2021-21656
was published
for
org.jenkins-ci.plugins:xcode-plugin
(Maven)
Mar 18, 2022
ProTip!
Advisories are also available from the
GraphQL API