GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
2,891
Erlang
24
GitHub Actions
39
Go
2,240
Maven
2,698
npm
2,899
NuGet
500
pip
2,728
Pub
5
RubyGems
364
Rust
889
Swift
19
Unreviewed advisories
All unreviewed
5,000+
147 advisories
Filter by severity
Improper Restriction of XML External Entity Reference in soa-model
Critical
CVE-2021-43090
was published
for
com.predic8:soa-model-core
(Maven)
Mar 26, 2022
XXE vulnerability in Jenkins Flaky Test Handler Plugin
High
CVE-2022-28140
was published
for
org.jenkins-ci.plugins:flaky-test-handler
(Maven)
Mar 30, 2022
Improper Restriction of XML External Entity Reference in Apache Batik
High
CVE-2017-5662
was published
for
org.apache.xmlgraphics:batik
(Maven)
May 13, 2022
XML External Entity Reference in RESTEasy
Moderate
CVE-2014-7839
was published
for
org.jboss.resteasy:resteasy-jaxrs
(Maven)
May 17, 2022
Apache SOAP's RPCRouterServlet allows reading of arbitrary files over HTTP
High
CVE-2022-40705
was published
for
soap:soap
(Maven)
Sep 23, 2022
Jenkins Plot Plugin XML External Entity Reference vulnerability
High
CVE-2022-46682
was published
for
org.jenkins-ci.plugins:plot
(Maven)
Dec 12, 2022
XML External Entity Reference in Apache NiFi
Moderate
CVE-2017-12623
was published
for
org.apache.nifi:nifi
(Maven)
May 17, 2022
Jenkins RQM Plugin vulnerable to Improper Restriction of XML External Entity Reference
Moderate
CVE-2022-41241
was published
for
net.praqma:rqm-plugin
(Maven)
Sep 22, 2022
XML Injection in Any23
Critical
CVE-2021-38555
was published
for
org.apache.any23:apache-any23
(Maven)
Sep 13, 2021
XXE vulnerability in Jenkins Parasoft Findings Plugin
High
CVE-2020-2178
was published
for
com.parasoft:parasoft-findings
(Maven)
May 24, 2022
Apache OpenMeetings does not correctly validate uploaded XML documents
Critical
CVE-2017-7664
was published
for
org.apache.openmeetings:openmeetings-parent
(Maven)
May 17, 2022
XML External Entity Reference vulnerability in Jenkins Pipeline: Phoenix AutoTest Plugin
High
CVE-2022-28155
was published
for
com.surenpi.jenkins:phoenix-autotest
(Maven)
Mar 30, 2022
XML External Entity Reference in edu.stanford.nlp:stanford-corenlp
Moderate
CVE-2022-0198
was published
for
edu.stanford.nlp:stanford-corenlp
(Maven)
Jan 14, 2022
Agent-to-controller security bypass in Jenkins Semantic Versioning Plugin
Critical
CVE-2023-24429
was published
for
org.jenkins-ci.plugins:semantic-versioning-plugin
(Maven)
Jan 26, 2023
XML External Entity Reference in ureport
High
CVE-2023-24187
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 14, 2023
XML External Entity (XXE) vulnerability in apoc.import.graphml
Moderate
GHSA-9vx8-f5c4-862x
was published
for
org.neo4j.procedure:apoc
(Maven)
Feb 24, 2023
Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf
Critical
CVE-2021-46849
was published
for
pikepdf
(pip)
Oct 24, 2022
•
withdrawn
Improper Restriction of XML External Entity Reference in com.h2database:h2.
High
CVE-2021-23463
was published
for
com.h2database:h2
(Maven)
Dec 16, 2021
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
Moderate
CVE-2016-5000
was published
for
org.apache.poi:poi-examples
(Maven)
May 13, 2022
XML External Entity Reference in Apache Sling
Critical
CVE-2016-6798
was published
for
org.apache.sling:org.apache.sling.xss
(Maven)
May 17, 2022
svg_optimizer rubygem external XML entity (XXE) vulnerability
Moderate
CVE-2023-46035
was published
for
svg_optimizer
(RubyGems)
Oct 20, 2023
kelvinmo simplexrd vulnerable to Improper Restriction of XML External Entity Reference
Critical
CVE-2015-10029
was published
for
kelvinmo/simplexrd
(Composer)
Jan 7, 2023
dssp vulnerable to Improper Restriction of XML External Entity Reference
Critical
CVE-2016-15011
was published
for
be.e_contract.dssp:dssp-client
(Maven)
Jan 6, 2023
bonita-connector-webservice XML External Entity vulnerability
Critical
CVE-2020-36640
was published
for
org.bonitasoft.connectors:bonita-connector-webservice
(Maven)
Jan 5, 2023
XXE vulnerability in Jenkins Job Import Plugin
Critical
CVE-2019-1003015
was published
for
org.jenkins-ci.plugins:job-import-plugin
(Maven)
May 13, 2022
ProTip!
Advisories are also available from the
GraphQL API