GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,356
Erlang
33
GitHub Actions
22
Go
2,121
Maven
5,000+
npm
3,783
NuGet
683
pip
3,465
Pub
12
RubyGems
893
Rust
892
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,062 advisories
Filter by severity
An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated,...
Moderate
Unreviewed
CVE-2017-3811
was published
May 17, 2022
XML External Entity Reference in Eclipse Lyo
Moderate
CVE-2021-41042
was published
for
org.eclipse.lyo:lyo-parent
(Maven)
Jul 8, 2022
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when...
High
Unreviewed
CVE-2017-1254
was published
May 17, 2022
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker...
High
Unreviewed
CVE-2022-35168
was published
Jul 13, 2022
Vulnerability that affects org.springframework.ws:spring-ws and org.springframework.ws:spring-xml
Critical
CVE-2019-3773
was published
for
org.springframework.ws:spring-ws
(Maven)
Jan 25, 2019
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when...
High
Unreviewed
CVE-2017-1322
was published
May 17, 2022
SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection...
Critical
Unreviewed
CVE-2022-23170
was published
Jun 25, 2022
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware...
Moderate
Unreviewed
CVE-2017-7907
was published
May 17, 2022
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity...
Critical
Unreviewed
CVE-2022-22489
was published
Aug 20, 2022
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system...
High
Unreviewed
CVE-2021-40510
was published
Jun 22, 2022
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions <...
High
Unreviewed
CVE-2022-32285
was published
Jun 15, 2022
ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4...
Critical
Unreviewed
CVE-2021-45024
was published
Jun 18, 2022
An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access...
High
Unreviewed
CVE-2022-31447
was published
Jun 15, 2022
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity...
Critical
Unreviewed
CVE-2017-1383
was published
May 17, 2022
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and...
Critical
Unreviewed
CVE-2016-7460
was published
May 17, 2022
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi...
Moderate
Unreviewed
CVE-2016-7458
was published
May 17, 2022
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when...
Moderate
Unreviewed
CVE-2017-1219
was published
May 17, 2022
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM...
Moderate
Unreviewed
CVE-2015-0194
was published
May 17, 2022
XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file...
Moderate
Unreviewed
CVE-2017-7457
was published
May 17, 2022
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if...
High
Unreviewed
CVE-2017-11390
was published
May 17, 2022
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers...
High
Unreviewed
CVE-2010-2245
was published
May 17, 2022
NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.
Critical
Unreviewed
CVE-2021-45981
was published
Jun 3, 2022
Improper Restriction of XML External Entity Reference in Stanford CoreNLP
Critical
CVE-2021-3878
was published
for
edu.stanford.nlp:stanford-corenlp
(Maven)
May 24, 2022
An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful...
High
Unreviewed
CVE-2022-31261
was published
May 25, 2022
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE)...
High
Unreviewed
CVE-2022-22977
was published
May 25, 2022
ProTip!
Advisories are also available from the
GraphQL API