GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,632
Erlang
34
GitHub Actions
25
Go
2,228
Maven
5,000+
npm
3,895
NuGet
701
pip
3,661
Pub
12
RubyGems
914
Rust
943
Swift
38
Unreviewed advisories
All unreviewed
5,000+
1,086 advisories
Filter by severity
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1...
Moderate
Unreviewed
CVE-2025-32406
was published
Apr 8, 2025
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps...
Moderate
Unreviewed
CVE-2025-32138
was published
Apr 4, 2025
The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server
High
CVE-2025-31487
was published
for
org.xwiki.contrib.jira:jira-macro-default
(Maven)
Apr 4, 2025
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Moderate
Unreviewed
CVE-2025-29932
was published
Mar 25, 2025
Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows...
Moderate
Unreviewed
CVE-2025-25036
was published
Mar 21, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
Moderate
CVE-2025-27136
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE...
High
Unreviewed
CVE-2025-0162
was published
Mar 7, 2025
External XML entity injection allows arbitrary download of files. The
score without least...
Moderate
Unreviewed
CVE-2025-24521
was published
Mar 5, 2025
Lucee RCE/XXE Vulnerability
Critical
CVE-2023-38693
was published
for
org.lucee:lucee
(Maven)
Mar 5, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity...
High
Unreviewed
CVE-2024-49781
was published
Feb 20, 2025
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2023-47160
was published
Feb 19, 2025
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a...
Moderate
Unreviewed
CVE-2024-25066
was published
Feb 17, 2025
IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing...
High
Unreviewed
CVE-2024-54171
was published
Feb 6, 2025
IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and...
High
Unreviewed
CVE-2024-49352
was published
Feb 5, 2025
XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`
High
CVE-2024-52807
was published
for
org.hl7.fhir.publisher:org.hl7.fhir.publisher.cli
(Maven)
Jan 24, 2025
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML...
Low
Unreviewed
CVE-2024-42185
was published
Jan 23, 2025
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
project, allowing an...
High
Unreviewed
CVE-2025-23195
was published
Jan 22, 2025
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete...
High
Unreviewed
CVE-2018-9375
was published
Jan 18, 2025
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of...
Moderate
Unreviewed
CVE-2018-9379
was published
Jan 18, 2025
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could...
High
Unreviewed
CVE-2024-12476
was published
Jan 17, 2025
ProTip!
Advisories are also available from the
GraphQL API