GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,743
Erlang
35
GitHub Actions
29
Go
2,315
Maven
5,000+
npm
3,949
NuGet
711
pip
3,729
Pub
12
RubyGems
920
Rust
965
Swift
38
Unreviewed advisories
All unreviewed
5,000+
346 advisories
Filter by severity
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration...
Moderate
Unreviewed
CVE-2025-4338
was published
May 23, 2025
Eclipse JGit XML External Entity (XXE) Vulnerability
Moderate
CVE-2025-4949
was published
for
org.eclipse.jgit:org.eclipse.jgit
(Maven)
May 21, 2025
Sulu vulnerable to XXE in SVG File upload Inspector
Moderate
CVE-2025-47778
was published
for
sulu/sulu
(Composer)
May 15, 2025
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An...
Moderate
Unreviewed
CVE-2025-34490
was published
Apr 28, 2025
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary...
Moderate
Unreviewed
CVE-2025-2070
was published
Apr 25, 2025
Overview
XML documents optionally contain a Document Type Definition (DTD), which, among...
Moderate
Unreviewed
CVE-2025-24911
was published
Apr 17, 2025
Overview
XML documents optionally contain a Document Type Definition (DTD), which, among...
Moderate
Unreviewed
CVE-2025-24910
was published
Apr 17, 2025
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1...
Moderate
Unreviewed
CVE-2025-32406
was published
Apr 8, 2025
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps...
Moderate
Unreviewed
CVE-2025-32138
was published
Apr 4, 2025
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Moderate
Unreviewed
CVE-2025-29932
was published
Mar 25, 2025
Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows...
Moderate
Unreviewed
CVE-2025-25036
was published
Mar 21, 2025
LocalS3 XML Parser Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-47qw-ccjm-9c2c
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Vulnerable to XML External Entity (XXE) Injection via Bucket Tagging API
Moderate
GHSA-v232-254c-m6p7
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 Project Bucket Operations Vulnerable to XML External Entity (XXE) Injection
Moderate
GHSA-2466-4485-4pxj
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
Moderate
CVE-2025-27136
was published
for
io.github.robothy:local-s3-rest
(Maven)
Mar 10, 2025
External XML entity injection allows arbitrary download of files. The
score without least...
Moderate
Unreviewed
CVE-2025-24521
was published
Mar 5, 2025
RSA Authentication Manager before 8.7 SP2 Patch 1 allows XML External Entity (XXE) attacks via a...
Moderate
Unreviewed
CVE-2024-25066
was published
Feb 17, 2025
In multiple functions of MiniThumbFile.java, there is a possible way to view the thumbnails of...
Moderate
Unreviewed
CVE-2018-9379
was published
Jan 18, 2025
We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB...
Moderate
Unreviewed
CVE-2024-12298
was published
Jan 14, 2025
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE...
Moderate
Unreviewed
CVE-2024-56356
was published
Dec 20, 2024
Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations...
Moderate
Unreviewed
CVE-2021-22501
was published
Dec 19, 2024
Microsoft SharePoint Information Disclosure Vulnerability
Moderate
Unreviewed
CVE-2024-49064
was published
Dec 12, 2024
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and...
Moderate
Unreviewed
CVE-2024-49535
was published
Dec 10, 2024
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 ...
Moderate
Unreviewed
CVE-2024-54005
was published
Dec 10, 2024
A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 ...
Moderate
Unreviewed
CVE-2024-49704
was published
Dec 10, 2024
ProTip!
Advisories are also available from the
GraphQL API