GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
467 advisories
Filter by severity
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and...
High
Unreviewed
CVE-2023-45727
was published
Oct 18, 2023
An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti...
High
Unreviewed
CVE-2023-38343
was published
Sep 21, 2023
Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client...
High
Unreviewed
CVE-2023-3892
was published
Sep 19, 2023
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to...
High
Unreviewed
CVE-2023-40239
was published
Sep 1, 2023
The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given...
High
Unreviewed
CVE-2023-37497
was published
Aug 4, 2023
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE)...
High
Unreviewed
CVE-2022-38840
was published
Jul 6, 2023
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common...
High
Unreviewed
CVE-2023-3113
was published
Jun 26, 2023
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks....
High
Unreviewed
CVE-2022-41221
was published
May 24, 2023
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE)....
High
Unreviewed
CVE-2023-27527
was published
May 10, 2023
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection ...
High
Unreviewed
CVE-2023-28008
was published
Apr 26, 2023
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when...
High
Unreviewed
CVE-2023-28009
was published
Apr 26, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2020-15419
was published
May 24, 2022
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2020-15418
was published
May 24, 2022
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin...
High
Unreviewed
CVE-2020-11885
was published
May 24, 2022
Oxygen XML Editor 21.1.1 allows XXE to read any file.
High
Unreviewed
CVE-2019-20191
was published
May 24, 2022
SAP NetWeaver Application Server Java (User Management Engine), versions- 7.10, 7.11, 7.20, 7.30,...
High
Unreviewed
CVE-2020-6202
was published
May 24, 2022
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19031
was published
May 24, 2022
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19032
was published
May 24, 2022
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
High
Unreviewed
CVE-2019-19998
was published
May 24, 2022
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow...
High
Unreviewed
CVE-2019-18227
was published
May 24, 2022
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the...
High
Unreviewed
CVE-2019-9757
was published
May 24, 2022
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
High
Unreviewed
CVE-2017-15725
was published
May 24, 2022
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection...
High
Unreviewed
CVE-2019-8087
was published
May 24, 2022
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection...
High
Unreviewed
CVE-2019-8086
was published
May 24, 2022
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection...
High
Unreviewed
CVE-2019-8082
was published
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API