GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
461 advisories
Filter by severity
An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The...
High
Unreviewed
CVE-2022-42301
was published
Oct 4, 2022
IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection ...
High
Unreviewed
CVE-2022-34348
was published
Sep 25, 2022
Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP
High
CVE-2022-40705
was published
for
soap:soap
(Maven)
Sep 23, 2022
Jenkins Compuware Common Configuration Plugin vulnerable to Improper Restriction of XML External Entity Reference
High
CVE-2022-41226
was published
for
com.compuware.jenkins:compuware-common-configuration
(Maven)
Sep 22, 2022
MEI2Volpiano is vulnerable to XML External Entity (XXE), leading to a Denial of Service (DoS)
High
CVE-2022-37189
was published
for
mei2volpiano
(pip)
Sep 8, 2022
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection...
High
Unreviewed
CVE-2022-36773
was published
Sep 2, 2022
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by...
High
Unreviewed
CVE-2022-2759
was published
Sep 1, 2022
Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus...
High
Unreviewed
CVE-2020-21641
was published
Aug 16, 2022
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with...
High
Unreviewed
CVE-2022-2458
was published
Aug 11, 2022
untangle vulnerable to Improper Restriction of XML External Entity Reference
High
CVE-2022-31471
was published
for
untangle
(pip)
Aug 6, 2022
An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a...
High
Unreviewed
CVE-2022-27873
was published
Jul 30, 2022
Access to external entities when parsing XML documents can lead to XML external entity (XXE)...
High
Unreviewed
CVE-2022-2414
was published
Jul 30, 2022
VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs...
High
Unreviewed
CVE-2021-42537
was published
Jul 28, 2022
Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient...
High
Unreviewed
CVE-2022-32458
was published
Jul 21, 2022
IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML...
High
Unreviewed
CVE-2022-22358
was published
Jul 20, 2022
Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker...
High
Unreviewed
CVE-2022-35168
was published
Jul 13, 2022
XML External Entity Reference in Jenkins Recipe Plugin
High
CVE-2022-34793
was published
for
org.jenkins-ci.plugins:recipe
(Maven)
Jul 1, 2022
XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system...
High
Unreviewed
CVE-2021-40510
was published
Jun 22, 2022
A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions <...
High
Unreviewed
CVE-2022-32285
was published
Jun 15, 2022
An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access...
High
Unreviewed
CVE-2022-31447
was published
Jun 15, 2022
An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful...
High
Unreviewed
CVE-2022-31261
was published
May 25, 2022
VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE)...
High
Unreviewed
CVE-2022-22977
was published
May 25, 2022
XML External Entity processing vulnerability in Pipeline Maven Integration Jenkins Plugin
High
CVE-2019-10327
was published
for
org.jenkins-ci.plugins:pipeline-maven
(Maven)
May 24, 2022
XXE vulnerability in Jenkins OWASP Dependency-Check Plugin
High
CVE-2021-43577
was published
for
org.jenkins-ci.plugins:dependency-check-jenkins-plugin
(Maven)
May 24, 2022
An improper restriction of XML external entity reference vulnerability in the parser of XML...
High
Unreviewed
CVE-2021-36172
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API