GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,343
Erlang
31
GitHub Actions
22
Go
2,107
Maven
5,000+
npm
3,764
NuGet
679
pip
3,452
Pub
12
RubyGems
892
Rust
886
Swift
37
Unreviewed advisories
All unreviewed
5,000+
60 advisories
Filter by severity
Samlify vulnerable to Authentication Bypass by allowing tokens to be reused with different usernames
High
CVE-2017-1000452
was published
for
samlify
(npm)
Jan 4, 2018
Ruby-saml allows attackers to perform XML signature wrapping attacks
High
CVE-2016-5697
was published
for
ruby-saml
(RubyGems)
Aug 21, 2018
Dom4j contains a XML Injection vulnerability
High
CVE-2018-1000632
was published
for
dom4j:dom4j
(Maven)
Oct 16, 2018
Apache Struts REST Plugin can potentially allow a DoS attack
High
CVE-2018-1327
was published
for
org.apache.struts:struts2-rest-plugin
(Maven)
Oct 16, 2018
XML Injection in python-libnmap
High
CVE-2019-1010017
was published
for
python-libnmap
(pip)
Jul 18, 2019
XXE in PHPSpreadsheet due to encoding issue
High
CVE-2018-19277
was published
for
phpoffice/phpspreadsheet
(Composer)
Nov 20, 2019
Layout XML Arbitrary Code Fix
High
CVE-2021-32758
was published
for
openmage/magento-lts
(Composer)
Aug 30, 2021
XML External Entity Injection in PyWPS
High
CVE-2021-39371
was published
for
pywps
(pip)
Sep 2, 2021
XML Injection in Crafter CMS Crafter Studio 3.0.1
High
CVE-2017-15685
was published
for
org.craftercms:crafter-studio
(Maven)
Feb 9, 2022
An issue was discovered in OverIT Geocall before 8.0. An authenticated user who has the Test...
High
Unreviewed
CVE-2022-22834
was published
Mar 11, 2022
A vulnerability in CLI of Cisco Firepower Threat Defense (FTD) Software could allow an...
High
Unreviewed
CVE-2022-20729
was published
May 4, 2022
D-Link DIR-865L has PHP File Inclusion in the router xml file.
High
Unreviewed
CVE-2013-4857
was published
May 5, 2022
An XML injection vulnerability in Junos OS CLI can allow a locally authenticated user to elevate...
High
Unreviewed
CVE-2017-10603
was published
May 13, 2022
SAP BusinessObjects Business Intelligence Platform (CMC Module), versions 4.10, 4.20 and 4.30,...
High
Unreviewed
CVE-2019-0268
was published
May 14, 2022
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not...
High
Unreviewed
CVE-2018-2477
was published
May 14, 2022
XML injection vulnerability exists in the file of DedeCMS V5.7 SP2 version, which can be utilized...
High
Unreviewed
CVE-2018-16785
was published
May 14, 2022
DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type=...
High
Unreviewed
CVE-2018-16784
was published
May 14, 2022
Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18,...
High
Unreviewed
CVE-2008-5024
was published
May 14, 2022
Openpsa contains a XML Injection vulnerability in RSS file upload feature that can result in...
High
Unreviewed
CVE-2018-1000526
was published
May 14, 2022
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an...
High
Unreviewed
CVE-2016-6272
was published
May 14, 2022
Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping...
High
Unreviewed
CVE-2015-3931
was published
May 17, 2022
Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks...
High
Unreviewed
CVE-2015-3932
was published
May 17, 2022
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may...
High
Unreviewed
CVE-2017-5654
was published
May 17, 2022
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
High
CVE-2013-4221
was published
for
org.restlet.jse:org.restlet
(Maven)
May 17, 2022
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0...
High
Unreviewed
CVE-2022-22784
was published
May 19, 2022
ProTip!
Advisories are also available from the
GraphQL API