GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,785
Erlang
36
GitHub Actions
29
Go
2,358
Maven
5,000+
npm
3,979
NuGet
720
pip
3,777
Pub
12
RubyGems
924
Rust
981
Swift
38
Unreviewed advisories
All unreviewed
5,000+
260 advisories
Filter by severity
Hudson XML API susceptible to External Entity Injection Vunerability prior to v3.3.2
Critical
CVE-2015-8031
was published
for
org.jvnet.hudson.main:hudson-core
(Maven)
Jul 15, 2022
Insufficient user input in Apache Jetspeed-2
Critical
CVE-2022-32533
was published
for
org.apache.portals.jetspeed-2:jetspeed-commons
(Maven)
Jul 7, 2022
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection...
Critical
Unreviewed
CVE-2022-23170
was published
Jun 25, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4...
Critical
Unreviewed
CVE-2021-45024
was published
Jun 18, 2022
XML External Entity Reference in drools
Critical
CVE-2021-41411
was published
for
org.drools:drools-core
(Maven)
Jun 17, 2022
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
Critical
Unreviewed
CVE-2021-45981
was published
Jun 3, 2022
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote...
Critical
Unreviewed
CVE-2021-34436
was published
May 24, 2022
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement...
Critical
Unreviewed
CVE-2020-25912
was published
May 24, 2022
Improper Restriction of XML External Entity Reference in Stanford CoreNLP
Critical
CVE-2021-3878
was published
for
edu.stanford.nlp:stanford-corenlp
(Maven)
May 24, 2022
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
Critical
Unreviewed
CVE-2021-38298
was published
May 24, 2022
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE)...
Critical
Unreviewed
CVE-2021-27741
was published
May 24, 2022
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file...
Critical
Unreviewed
CVE-2021-34823
was published
May 24, 2022
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes...
Critical
Unreviewed
CVE-2021-37425
was published
May 24, 2022
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External...
Critical
Unreviewed
CVE-2021-20399
was published
May 24, 2022
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Critical
Unreviewed
CVE-2021-35066
was published
May 24, 2022
XXE vulnerability in Jenkins Generic Webhook Trigger Plugin
Critical
CVE-2021-21669
was published
for
org.jenkins-ci.plugins:generic-webhook-trigger
(Maven)
May 24, 2022
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE)...
Critical
Unreviewed
CVE-2020-5003
was published
May 24, 2022
XML external entity vulnerability in Jenkins Nuget Plugin
Critical
CVE-2021-21658
was published
for
org.jenkins-ci.plugins:nuget
(Maven)
May 24, 2022
XML External Entity Resolution (XXE) in Helix ALM. The XML Import functionality of the...
Critical
Unreviewed
CVE-2021-29997
was published
May 24, 2022
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a...
Critical
Unreviewed
CVE-2021-1628
was published
May 24, 2022
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API...
Critical
Unreviewed
CVE-2021-27931
was published
May 24, 2022
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via...
Critical
Unreviewed
CVE-2021-26703
was published
May 24, 2022
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
Critical
Unreviewed
CVE-2020-35604
was published
May 24, 2022
yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.
Critical
Unreviewed
CVE-2020-25215
was published
May 24, 2022
Improper Restriction of XML External Entity Reference in Mulesoft APIkit
Critical
CVE-2020-10991
was published
for
org.mule.modules:mule-apikit-module
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API