GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,779
Erlang
36
GitHub Actions
29
Go
2,338
Maven
5,000+
npm
3,972
NuGet
714
pip
3,769
Pub
12
RubyGems
923
Rust
976
Swift
38
Unreviewed advisories
All unreviewed
5,000+
495 advisories
Filter by severity
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15
is vulnerable to an XML external...
High
Unreviewed
CVE-2025-36049
was published
Jun 18, 2025
Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can...
High
Unreviewed
CVE-2025-44044
was published
Jun 10, 2025
GeoNetwork affected by XML External Entity (XXE) processing vulnerability in WFS indexing REST API endpoint
High
GHSA-2p76-gc46-5fvc
was published
for
org.geonetwork-opensource:gn-web-app
(Maven)
Jun 10, 2025
[XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
High
CVE-2025-30220
was published
for
org.geoserver.web:gs-web-app
(Maven)
Jun 10, 2025
PHPOffice Math allows XXE when processing an XML file in the MathML format
High
CVE-2025-48882
was published
for
phpoffice/math
(Composer)
May 29, 2025
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This...
High
Unreviewed
CVE-2025-27523
was published
May 15, 2025
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method...
High
Unreviewed
CVE-2025-4639
was published
May 14, 2025
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All...
High
Unreviewed
CVE-2024-51445
was published
May 13, 2025
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated...
High
Unreviewed
CVE-2025-30018
was published
May 13, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper...
High
Unreviewed
CVE-2025-22478
was published
May 6, 2025
Langroid Allows XXE Injection via XMLToolMessage
High
CVE-2025-46726
was published
for
langroid
(pip)
May 5, 2025
Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before...
High
Unreviewed
CVE-2022-21220
was published
Feb 11, 2022
Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R)...
High
Unreviewed
CVE-2022-21205
was published
Feb 11, 2022
XXE vulnerability in Jenkins JAPEX Plugin
High
CVE-2022-45400
was published
for
org.jvnet.hudson.plugins:japex
(Maven)
Nov 16, 2022
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can...
High
Unreviewed
CVE-2022-40304
was published
Nov 23, 2022
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an...
High
Unreviewed
CVE-2017-12216
was published
May 13, 2022
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows...
High
Unreviewed
CVE-2017-9233
was published
May 13, 2022
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted...
High
Unreviewed
CVE-2017-1000061
was published
May 13, 2022
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
High
Unreviewed
CVE-2017-1000021
was published
May 14, 2022
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved...
High
Unreviewed
CVE-2017-6662
was published
May 14, 2022
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote...
High
Unreviewed
CVE-2017-8913
was published
May 13, 2022
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib...
High
Unreviewed
CVE-2017-6055
was published
May 17, 2022
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0...
High
Unreviewed
CVE-2016-4312
was published
May 14, 2022
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly...
High
Unreviewed
CVE-2020-14478
was published
Feb 25, 2022
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update...
High
Unreviewed
CVE-2016-4264
was published
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API