GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
104 advisories
Filter by severity
Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior....
High
Unreviewed
CVE-2021-2322
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs...
High
Unreviewed
CVE-2021-31598
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs...
Moderate
Unreviewed
CVE-2021-31347
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs...
Moderate
Unreviewed
CVE-2021-31348
was published
May 24, 2022
Magento XML injection in the Widgets module
Critical
CVE-2021-21019
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XPath Injection
Critical
CVE-2021-21025
was published
for
magento/community-edition
(Composer)
May 24, 2022
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which...
High
Unreviewed
CVE-2020-29599
was published
May 24, 2022
XML injection in Crafter CMS
High
CVE-2017-15683
was published
for
org.craftercms:crafter-core
(Maven)
May 24, 2022
yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an...
Critical
Unreviewed
CVE-2020-25216
was published
May 24, 2022
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1...
Moderate
Unreviewed
CVE-2020-3846
was published
May 24, 2022
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML...
Moderate
Unreviewed
CVE-2019-20201
was published
May 24, 2022
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19032
was published
May 24, 2022
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19031
was published
May 24, 2022
Modoboa is vulnerable to an XML External Entity Injection (XXE)
High
CVE-2019-19702
was published
for
modoboa-dmarc
(pip)
May 24, 2022
Magento 2 Community Edition XML Injection
Critical
CVE-2019-8158
was published
for
magento/community-edition
(Composer)
May 24, 2022
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via...
High
Unreviewed
CVE-2019-17323
was published
May 24, 2022
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka...
High
Unreviewed
CVE-2019-18213
was published
May 24, 2022
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1,...
Moderate
Unreviewed
CVE-2019-0370
was published
May 24, 2022
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used...
High
Unreviewed
CVE-2019-4539
was published
May 24, 2022
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if...
Critical
Unreviewed
CVE-2019-16941
was published
May 24, 2022
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is...
Critical
Unreviewed
CVE-2019-14277
was published
May 24, 2022
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a...
High
Unreviewed
CVE-2019-12787
was published
May 24, 2022
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0...
High
Unreviewed
CVE-2022-22784
was published
May 19, 2022
XML Injection in Apache Solr
Moderate
CVE-2013-6408
was published
for
org.apache.solr:solr-core
(Maven)
May 17, 2022
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
High
CVE-2013-4221
was published
for
org.restlet.jse:org.restlet
(Maven)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API