Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

96 advisories

Loading
Ruby-saml allows attackers to perform XML signature wrapping attacks High
CVE-2016-5697 was published for ruby-saml (RubyGems) Aug 21, 2018
Dom4j contains a XML Injection vulnerability High
CVE-2018-1000632 was published for dom4j:dom4j (Maven) Oct 16, 2018
Apache Struts REST Plugin can potentially allow a DoS attack High
CVE-2018-1327 was published for org.apache.struts:struts2-rest-plugin (Maven) Oct 16, 2018
sunSUNQ
XML Injection in python-libnmap High
CVE-2019-1010017 was published for python-libnmap (pip) Jul 18, 2019
XXE in PHPSpreadsheet due to encoding issue High
CVE-2018-19277 was published for phpoffice/phpspreadsheet (Composer) Nov 20, 2019
MarkLee131
Duplicate Advisory: XML Injection in petl Critical
GHSA-69q2-p9xp-739v was published for petl (pip) Apr 20, 2021 withdrawn
Layout XML Arbitrary Code Fix High
CVE-2021-32758 was published for openmage/magento-lts (Composer) Aug 30, 2021
XML External Entity Injection in PyWPS High
CVE-2021-39371 was published for pywps (pip) Sep 2, 2021
tdunlap607
Infinite Loop in Apache Xerces Java Moderate
CVE-2022-23437 was published for xerces:xercesImpl (Maven) Jan 27, 2022
XML Injection in Crafter CMS Crafter Studio 3.0.1 High
CVE-2017-15685 was published for org.craftercms:crafter-studio (Maven) Feb 9, 2022
ALIN MDaemon Security Gateway through 8.5.0 allows XML Injection. Moderate Unreviewed
CVE-2022-25356 was published Apr 6, 2022
XML Injection in Xerces Java affects Nokogiri Moderate
GHSA-xxx9-3xcr-gjj3 was published for nokogiri (RubyGems) Apr 11, 2022
D-Link DIR-865L has PHP File Inclusion in the router xml file. High Unreviewed
CVE-2013-4857 was published May 5, 2022
ProTip! Advisories are also available from the GraphQL API