GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
311 advisories
Filter by severity
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2682
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2681
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
Moderate
CVE-2016-5000
was published
for
org.apache.poi:poi-examples
(Maven)
May 13, 2022
KNIME Analytics Platform before 4.5.0 is vulnerable to XXE (external XML entity injection) via a...
Moderate
Unreviewed
CVE-2021-45096
was published
Dec 17, 2021
svg_optimizer rubygem external XML entity (XXE) vulnerability
Moderate
CVE-2023-46035
was published
for
svg_optimizer
(RubyGems)
Oct 20, 2023
Umbraco CMS XXE Vulnerability
Moderate
CVE-2017-15280
was published
for
UmbracoCms.Web
(NuGet)
May 17, 2022
Jenkins Self-Organizing Swarm Plug-in Modules Plugin XXE vulnerability via UDP broadcast response
Moderate
CVE-2019-10309
was published
for
org.jenkins-ci.plugins:swarm
(Maven)
May 24, 2022
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used...
Moderate
Unreviewed
CVE-2020-26513
was published
May 24, 2022
XXE vulnerability in Jenkins Nerrvana Plugin
Moderate
CVE-2020-2298
was published
for
org.jenkins-ci.plugins:nerrvana-plugin
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Selenium HTML report Plugin
Moderate
CVE-2021-21672
was published
for
org.jenkins-ci.plugins:seleniumhtmlreport
(Maven)
Jul 2, 2021
XXE vulnerability in Jenkins Performance Plugin
Moderate
CVE-2021-21701
was published
for
org.jenkins-ci.plugins:performance
(Maven)
May 24, 2022
XXE vulnerability in Jenkins pom2config Plugin
Moderate
CVE-2021-43576
was published
for
org.jenkins-ci.plugins:pom2config
(Maven)
May 24, 2022
XML External Entity Reference in Jenkins Violations Plugin
Moderate
CVE-2022-45386
was published
for
org.jenkins-ci.plugins:violations
(Maven)
Nov 16, 2022
XML External Entity (XXE) vulnerability in the XML data handler
Moderate
CVE-2023-38490
was published
for
getkirby/cms
(Composer)
Jul 28, 2023
Jenkins External Monitor Job Type Plugin XML external entity vulnerability
Moderate
CVE-2023-37942
was published
for
org.jenkins-ci.plugins:external-monitor-job
(Maven)
Jul 12, 2023
An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the...
Moderate
Unreviewed
CVE-2022-34832
was published
Oct 27, 2023
DDFFileParser is vulnerable to XXE Attacks
Moderate
CVE-2023-41034
was published
for
org.eclipse.leshan:leshan-core
(Maven)
Aug 31, 2023
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by...
Moderate
Unreviewed
CVE-2023-2806
was published
May 19, 2023
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine ...
Moderate
Unreviewed
CVE-2023-20173
was published
May 18, 2023
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine ...
Moderate
Unreviewed
CVE-2023-20174
was published
May 18, 2023
Esoteric YamlBeans XML Entity Expansion vulnerability
Moderate
CVE-2023-24620
was published
for
com.esotericsoftware.yamlbeans:yamlbeans
(Maven)
Aug 25, 2023
CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper...
Moderate
Unreviewed
CVE-2023-43624
was published
Oct 23, 2023
A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated,...
Moderate
Unreviewed
CVE-2020-26064
was published
Aug 4, 2023
Duplicate Advisory: Eclipse IDE XXE in eclipse.platform
Moderate
GHSA-cc4w-3cff-j8fw
was published
for
org.eclipse.platform:eclipse.platform
(Maven)
Nov 9, 2023
•
withdrawn
XXE vulnerability in Jenkins Mercurial Plugin
Moderate
CVE-2020-2305
was published
for
org.jenkins-ci.plugins:mercurial
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API