GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,810
Erlang
36
GitHub Actions
31
Go
2,396
Maven
5,000+
npm
4,030
NuGet
721
pip
3,820
Pub
12
RubyGems
932
Rust
988
Swift
38
Unreviewed advisories
All unreviewed
5,000+
355 advisories
Filter by severity
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0...
Moderate
Unreviewed
CVE-2016-0284
was published
May 17, 2022
NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML...
Moderate
Unreviewed
CVE-2016-5749
was published
May 17, 2022
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read...
Moderate
Unreviewed
CVE-2017-6344
was published
May 17, 2022
Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.
Moderate
Unreviewed
CVE-2022-34001
was published
Jul 20, 2022
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote...
Moderate
Unreviewed
CVE-2015-7743
was published
May 17, 2022
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.
Moderate
Unreviewed
CVE-2016-4931
was published
May 17, 2022
External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access...
Moderate
Unreviewed
CVE-2016-5748
was published
May 17, 2022
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity ...
Moderate
Unreviewed
CVE-2017-8056
was published
May 17, 2022
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to...
Moderate
Unreviewed
CVE-2017-2308
was published
May 17, 2022
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an...
Moderate
Unreviewed
CVE-2016-0254
was published
May 17, 2022
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated,...
Moderate
Unreviewed
CVE-2017-3811
was published
May 17, 2022
XML External Entity Reference in Eclipse Lyo
Moderate
CVE-2021-41042
was published
for
org.eclipse.lyo:lyo-parent
(Maven)
Jul 8, 2022
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi...
Moderate
Unreviewed
CVE-2016-7458
was published
May 17, 2022
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when...
Moderate
Unreviewed
CVE-2017-1219
was published
May 17, 2022
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM...
Moderate
Unreviewed
CVE-2015-0194
was published
May 17, 2022
XML External Entity Reference in RESTEasy
Moderate
CVE-2014-7839
was published
for
org.jboss.resteasy:resteasy-jaxrs
(Maven)
May 17, 2022
Improper Restriction of XML External Entity Reference in Apache uimaj
Moderate
CVE-2017-15691
was published
for
org.apache.uima:uimafit-core
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in Elasticsearch
Moderate
CVE-2018-17247
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Castor
Moderate
CVE-2014-3004
was published
for
org.codehaus.castor:castor
(Maven)
May 13, 2022
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could...
Moderate
Unreviewed
CVE-2022-0221
was published
Apr 14, 2022
Improper Restriction of XML External Entity Reference in wutka jox
Moderate
CVE-2021-43142
was published
for
com.wutka:jox
(Maven)
Apr 1, 2022
When opening a malicious solution file provided by an attacker, the application suffers from an...
Moderate
Unreviewed
CVE-2022-1018
was published
Apr 3, 2022
A XML Extended entity vulnerability in McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10...
Moderate
Unreviewed
CVE-2022-0861
was published
Mar 24, 2022
XML External Entities Vulnerability in CVRF-CSAF-Converter
Moderate
CVE-2022-27193
was published
for
cvrf2csaf
(pip)
Mar 16, 2022
Authenticated XML External Entity Processing
Moderate
GHSA-8xv9-qcr9-ww9j
was published
for
shopware/core
(Composer)
Oct 19, 2020
ProTip!
Advisories are also available from the
GraphQL API