GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
152 advisories
Filter by severity
Jenkins Maven Release Plug-in Plugin XXE vulnerability
High
CVE-2019-16549
was published
for
org.jenkins-ci.plugins.m2release:m2release
(Maven)
May 24, 2022
Jenkins 360 FireLine Plugin vulnerable to XML External Entity Reference
High
CVE-2019-10466
was published
for
org.jenkins-ci.plugins.plugin:fireline
(Maven)
May 24, 2022
Improper Restriction of XML External Entity Reference Jenkins Token Macro Plugin
High
CVE-2019-10337
was published
for
org.jenkins-ci.plugins:token-macro
(Maven)
May 24, 2022
XML External Entity Reference in Jenkins Storable Configs Plugin
High
CVE-2022-30971
was published
for
org.jvnet.hudson.plugins:storable-configs-plugin
(Maven)
May 18, 2022
CakePHPallows remote attackers to read arbitrary files via XML data containing external entity references
High
CVE-2012-4399
was published
for
cakephp/cakephp
(Composer)
May 17, 2022
Zend Framework XXE Vulnerability
High
CVE-2012-3363
was published
for
zendframework/zendframework1
(Composer)
May 17, 2022
Improper Restriction of XML External Entity Reference in Apache Solr
High
CVE-2012-6612
was published
for
org.apache.solr:solr-core
(Maven)
May 17, 2022
getID3 is vulnerable to XML External Entity (XXE)
High
CVE-2014-2053
was published
for
james-heinrich/getid3
(Composer)
May 17, 2022
XML External Entity Reference in org.picketlink:picketlink-common
High
CVE-2014-3530
was published
for
org.picketlink:picketlink-common
(Maven)
May 14, 2022
XXE Vulnerability in XMLBundle 0.1.7
High
CVE-2017-1000477
was published
for
desperado/xml-bundle
(Composer)
May 14, 2022
XXE vulnerability in Jenkins DRY Plugin
High
CVE-2018-1000010
was published
for
org.jvnet.hudson.plugins:dry
(Maven)
May 14, 2022
XXE vulnerability in Jenkins Checkstyle Plugin
High
CVE-2018-1000009
was published
for
org.jvnet.hudson.plugins:checkstyle
(Maven)
May 14, 2022
XXE vulnerability in Jenkins PMD Plugin
High
CVE-2018-1000008
was published
for
org.jvnet.hudson.plugins:pmd
(Maven)
May 14, 2022
XML External Entity Reference in Jenkins FindBugs Plugin
High
CVE-2018-1000011
was published
for
org.jvnet.hudson.plugins.findbugs:library
(Maven)
May 14, 2022
XXE vulnerability Jenkins Warnings Plugin
High
CVE-2018-1000012
was published
for
org.jvnet.hudson.plugins:warnings
(Maven)
May 14, 2022
XXE vulnerability in Jenkins Android Lint Plugin
High
CVE-2018-1000055
was published
for
org.jvnet.hudson.plugins:android-lint
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in Jenkins JUnit Plugin
High
CVE-2018-1000056
was published
for
org.jenkins-ci.plugins:junit
(Maven)
May 14, 2022
Jenkins CCM Plugin vulnerable to Improper Restriction of XML External Entity Reference
High
CVE-2018-1000054
was published
for
org.jvnet.hudson.plugins:ccm
(Maven)
May 14, 2022
WeChat Pay Java SDK allows XXE
High
CVE-2018-13439
was published
for
com.github.wxpay:wxpay-sdk
(Maven)
May 14, 2022
XML External Entity Reference in Apache Cayenne
High
CVE-2018-11758
was published
for
org.apache.cayenne:cayenne-parent
(Maven)
May 14, 2022
Apache XML-RPC XXE Vulnerability
High
CVE-2016-5002
was published
for
org.apache.xmlrpc:xmlrpc
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in PMD
High
CVE-2019-7722
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in iText
High
CVE-2017-9096
was published
for
com.itextpdf:itextpdf
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache Batik
High
CVE-2017-5662
was published
for
org.apache.xmlgraphics:batik
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
High
CVE-2016-8739
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API