GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,299
Erlang
31
GitHub Actions
21
Go
2,065
Maven
5,000+
npm
3,744
NuGet
668
pip
3,425
Pub
12
RubyGems
892
Rust
877
Swift
36
Unreviewed advisories
All unreviewed
5,000+
469 advisories
Filter by severity
XXE vulnerability in Jenkins Filesystem Trigger Plugin
High
CVE-2021-21657
was published
for
org.jenkins-ci.plugins:fstrigger
(Maven)
May 24, 2022
XXE vulnerability in Jenkins URLTrigger Plugin
High
CVE-2021-21659
was published
for
org.jenkins-ci.plugins:urltrigger
(Maven)
May 24, 2022
XXE vulnerability in Jenkins Liquibase Runner Plugin
High
CVE-2020-2284
was published
for
org.jenkins-ci.plugins:liquibase-runner
(Maven)
May 24, 2022
dd-plist XML External Entitly vulnerability
High
CVE-2016-15026
was published
for
com.googlecode.plist:dd-plist
(Maven)
Feb 20, 2023
Restlet Framework Ja-rs extension is vulnerable to XXE when using SimpleXMLProvider
High
CVE-2017-14868
was published
for
org.restlet.jse:org.restlet.ext.jaxrs
(Maven)
Oct 17, 2018
Improper Restriction of XML External Entity Reference in com.h2database:h2.
High
CVE-2021-23463
was published
for
com.h2database:h2
(Maven)
Dec 16, 2021
WeChat Pay Java SDK allows XXE
High
CVE-2018-13439
was published
for
com.github.wxpay:wxpay-sdk
(Maven)
May 14, 2022
XXE Vulnerability in XMLBundle 0.1.7
High
CVE-2017-1000477
was published
for
desperado/xml-bundle
(Composer)
May 14, 2022
Jenkins AbsInt a³ Plugin XML External Entity Reference vulnerability
High
CVE-2023-28685
was published
for
org.jenkins-ci.plugins:absint-a3
(Maven)
Jul 6, 2023
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with...
High
Unreviewed
CVE-2022-2458
was published
Aug 11, 2022
Improper Restriction of XML External Entity Reference (XXE) in Nokogiri on JRuby
High
CVE-2021-41098
was published
for
nokogiri
(RubyGems)
Sep 27, 2021
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing...
High
Unreviewed
CVE-2023-27876
was published
Apr 7, 2023
Jenkins Crap4J Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28680
was published
for
org.jenkins-ci.plugins:crap4j
(Maven)
Apr 2, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2022-36969
was published
Mar 29, 2023
Jenkins remote-jobs-view-plugin vulnerable to XML external entity attacks
High
CVE-2023-28684
was published
for
com.sap.jenkinsci:remote-jobs-view-plugin
(Maven)
Apr 2, 2023
Jenkins Visual Studio Code Metrics Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28681
was published
for
org.jenkins-ci.plugins:vs-code-metrics
(Maven)
Apr 2, 2023
Jenkins Performance Publisher Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28682
was published
for
org.jenkins-ci.plugins:perfpublisher
(Maven)
Apr 2, 2023
Jenkins Phabricator Differential Plugin vulnerable to XML external entity (XXE) attacks
High
CVE-2023-28683
was published
for
org.jenkins-ci.plugins:phabricator-plugin
(Maven)
Apr 2, 2023
Restlet Framework allows remote attackers to access arbitrary files via a crafted REST API HTTP request
High
CVE-2017-14949
was published
for
org.restlet.jse:org.restlet
(Maven)
Oct 17, 2018
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when...
High
Unreviewed
CVE-2023-27874
was published
Mar 21, 2023
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious...
High
Unreviewed
CVE-2023-20855
was published
Feb 22, 2023
XWiki Platform vulnerable to data leak via Improper Restriction of XML External Entity Reference
High
CVE-2023-27480
was published
for
org.xwiki.platform:xwiki-platform-xar-model
(Maven)
Mar 8, 2023
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the...
High
Unreviewed
CVE-2021-33950
was published
Feb 17, 2023
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection...
High
Unreviewed
CVE-2023-24323
was published
Feb 9, 2023
XML External Entity Reference in ureport
High
CVE-2023-24187
was published
for
com.bstek.ureport:ureport2-core
(Maven)
Feb 14, 2023
ProTip!
Advisories are also available from the
GraphQL API