GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
116
GitHub Actions
55
Go
4,701
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,566
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
273 advisories
Filter by severity
Lucee RCE/XXE Vulnerability
Critical
CVE-2023-38693
was published
for
org.lucee:lucee
(Maven)
Mar 5, 2025
Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). ...
Critical
Unreviewed
CVE-2024-21082
was published
Apr 17, 2024
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
Critical
Unreviewed
CVE-2022-47873
was published
Feb 1, 2023
XML external entity vulnerability on agents in Jenkins MSTest Plugin
Critical
CVE-2023-24441
was published
for
org.jvnet.hudson.plugins:mstest
(Maven)
Jan 26, 2023
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1...
Critical
Unreviewed
CVE-2016-3974
was published
May 13, 2022
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not...
Critical
Unreviewed
CVE-2015-8866
was published
May 14, 2022
USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data...
Critical
Unreviewed
CVE-2017-6895
was published
May 17, 2022
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE)...
Critical
Unreviewed
CVE-2016-6256
was published
May 14, 2022
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
Critical
Unreviewed
CVE-2015-7241
was published
May 14, 2022
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML...
Critical
Unreviewed
CVE-2014-0030
was published
May 14, 2022
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2...
Critical
Unreviewed
CVE-2014-3630
was published
May 13, 2022
XML External Entity Reference in Jenkins CCCC Plugin
Critical
CVE-2022-45395
was published
for
com.thalesgroup.jenkins-ci.plugins:cccc
(Maven)
Nov 16, 2022
WSO2 API Manager XML External Entity (XXE) vulnerability
Critical
CVE-2025-2905
was published
for
org.wso2.am:am-distribution-parent
(Maven)
May 5, 2025
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE)...
Critical
Unreviewed
CVE-2025-2777
was published
May 7, 2025
BoniGarcia WebDriverManager Affected By Improper Restriction of XML External Entity Reference
Critical
CVE-2025-4641
was published
for
io.github.bonigarcia:webdrivermanager
(Maven)
May 14, 2025
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML...
Critical
Unreviewed
CVE-2023-28151
was published
Mar 24, 2023
An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external...
Critical
Unreviewed
CVE-2023-28150
was published
Mar 25, 2023
An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external...
Critical
Unreviewed
CVE-2023-28152
was published
Mar 24, 2023
Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon...
Critical
Unreviewed
CVE-2025-31039
was published
Jun 9, 2025
GeoTools has XML External Entity (XXE) Processing Vulnerability in XSD schema handling
Critical
GHSA-826p-4gcg-35vw
was published
for
org.geotools:gt-wfs-ng
(Maven)
Jun 9, 2025
GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
Critical
CVE-2024-34711
was published
for
org.geoserver.main:gs-main
(Maven)
Jun 10, 2025
An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code...
Critical
Unreviewed
CVE-2023-26999
was published
Jan 9, 2024
Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Mulesoft APIkit
Critical
CVE-2020-10991
was published
for
org.mule.modules:mule-apikit-module
(Maven)
May 24, 2022
•
withdrawn
ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction...
Critical
Unreviewed
CVE-2025-49535
was published
Jul 8, 2025
Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Critical
CVE-2015-3208
was published
for
org.apache.activemq:activemq-client
(Maven)
May 14, 2022
•
withdrawn
ProTip!
Advisories are also available from the
GraphQL API