GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,293
Erlang
31
GitHub Actions
21
Go
2,061
Maven
5,000+
npm
3,744
NuGet
668
pip
3,423
Pub
12
RubyGems
892
Rust
875
Swift
36
Unreviewed advisories
All unreviewed
5,000+
43 advisories
Filter by severity
Moderate severity vulnerability that affects org.restlet.jse:org.restlet
Moderate
CVE-2014-1868
was published
for
org.restlet.jse:org.restlet
(Maven)
Oct 17, 2018
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be...
Moderate
Unreviewed
CVE-2021-20464
was published
Apr 23, 2022
Improper Restriction of Recursive Entity References in DTDs in Apache POI
Moderate
CVE-2017-5644
was published
for
org.apache.poi:poi
(Maven)
May 13, 2022
A vulnerability has been identified in Mendix Excel Importer Module (Mendix 8 compatible) (All...
Moderate
Unreviewed
CVE-2022-34467
was published
Jul 13, 2022
In Linaro Automated Validation Architecture (LAVA) before 2022.11, users with valid credentials...
Moderate
Unreviewed
CVE-2022-44641
was published
Nov 18, 2022
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0...
Moderate
Unreviewed
CVE-2019-20104
was published
May 24, 2022
An issue was discovered in SmartClient 12.0. The Remote Procedure Call (RPC) saveFile provided by...
Moderate
Unreviewed
CVE-2020-9354
was published
May 24, 2022
IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML...
Moderate
Unreviewed
CVE-2020-4481
was published
May 24, 2022
IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack...
Moderate
Unreviewed
CVE-2020-4377
was published
May 24, 2022
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML...
Moderate
Unreviewed
CVE-2020-24589
was published
May 24, 2022
Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3...
Moderate
Unreviewed
CVE-2020-24052
was published
May 24, 2022
The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates....
Moderate
Unreviewed
CVE-2020-24591
was published
May 24, 2022
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML...
Moderate
Unreviewed
CVE-2020-27017
was published
May 24, 2022
The Dashboard Editor in Hitachi Vantara Pentaho through 7.x - 8.x contains an XML Entity...
Moderate
Unreviewed
CVE-2020-24665
was published
May 24, 2022
Infoblox NIOS before 8.5.2 allows entity expansion during an XML upload operation, a related...
Moderate
Unreviewed
CVE-2020-15303
was published
May 24, 2022
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all...
Moderate
Unreviewed
CVE-2021-3541
was published
May 24, 2022
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior...
Moderate
Unreviewed
CVE-2021-31842
was published
May 24, 2022
Nokogiri vulnerable to DoS while parsing XML documents
Moderate
CVE-2013-6460
was published
for
nokogiri
(RubyGems)
May 5, 2022
Nokogiri vulnerable to DoS while parsing XML entities
Moderate
CVE-2013-6461
was published
for
nokogiri
(RubyGems)
May 5, 2022
Quadratic blowup in Convert::xml2array()
Moderate
CVE-2021-41559
was published
for
silverstripe/framework
(Composer)
Jun 29, 2022
Nokogiri vulnerable to libxml XML Entity Expansion
Moderate
CVE-2015-1819
was published
for
nokogiri
(RubyGems)
Aug 8, 2018
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2683
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Several Zend Products Vulnerable to XXE and XEE attacks
Moderate
CVE-2014-2682
was published
for
zendframework/zendframework1
(Composer)
May 14, 2022
Withdrawn Advisory: dom4j XML Entity Expansion vulnerability
Moderate
CVE-2023-45960
was published
for
org.dom4j:dom4j
(Maven)
Oct 25, 2023
•
withdrawn
Zend Framework XEE Vulnerability
Moderate
CVE-2012-6532
was published
for
zendframework/zendframework1
(Composer)
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API