GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,354
Erlang
31
GitHub Actions
22
Go
2,120
Maven
5,000+
npm
3,779
NuGet
681
pip
3,460
Pub
12
RubyGems
892
Rust
888
Swift
38
Unreviewed advisories
All unreviewed
5,000+
61 advisories
Filter by severity
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a...
High
Unreviewed
CVE-2019-12787
was published
May 24, 2022
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used...
High
Unreviewed
CVE-2019-4539
was published
May 24, 2022
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka...
High
Unreviewed
CVE-2019-18213
was published
May 24, 2022
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via...
High
Unreviewed
CVE-2019-17323
was published
May 24, 2022
Modoboa is vulnerable to an XML External Entity Injection (XXE)
High
CVE-2019-19702
was published
for
modoboa-dmarc
(pip)
May 24, 2022
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19032
was published
May 24, 2022
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19031
was published
May 24, 2022
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate...
High
Unreviewed
CVE-2020-0646
was published
May 24, 2022
XML injection in Crafter CMS
High
CVE-2017-15683
was published
for
org.craftercms:crafter-core
(Maven)
May 24, 2022
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which...
High
Unreviewed
CVE-2020-29599
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs...
High
Unreviewed
CVE-2021-31598
was published
May 24, 2022
Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior....
High
Unreviewed
CVE-2021-2322
was published
May 24, 2022
OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via...
High
Unreviewed
CVE-2021-36359
was published
May 24, 2022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are...
High
Unreviewed
CVE-2021-36020
was published
May 24, 2022
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack...
High
Unreviewed
CVE-2018-1721
was published
May 24, 2022
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and...
High
Unreviewed
CVE-2020-8479
was published
May 24, 2022
CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could...
High
Unreviewed
CVE-2022-33739
was published
Jun 17, 2022
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with...
High
Unreviewed
CVE-2022-2458
was published
Aug 11, 2022
XML injection in the Intel(R) Quartus Prime Pro and Standard edition software may allow an...
High
Unreviewed
CVE-2022-27233
was published
Nov 11, 2022
Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High
CVE-2022-46464
was published
for
concrete5/concrete5
(Composer)
Dec 6, 2022
•
withdrawn
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to...
High
Unreviewed
CVE-2022-35259
was published
Dec 6, 2022
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0...
High
Unreviewed
CVE-2023-27253
was published
Mar 18, 2023
Adobe Commerce versions 2.4.4-p2 (and earlier) and 2.4.5-p1 (and earlier) are affected by an XML...
High
Unreviewed
CVE-2023-22247
was published
Mar 27, 2023
Umbraco CMS 7.12.4 allows Remote Code Execution by authenticated administrators via msxsl:script...
High
Unreviewed
CVE-2019-25137
was published
May 18, 2023
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier)...
High
Unreviewed
CVE-2023-38207
was published
Aug 9, 2023
ProTip!
Advisories are also available from the
GraphQL API