GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
99 advisories
Filter by severity
Magento XPath Injection
Critical
CVE-2021-21025
was published
for
magento/community-edition
(Composer)
May 24, 2022
ImageMagick before 6.9.11-40 and 7.x before 7.0.10-40 mishandles the -authenticate option, which...
High
Unreviewed
CVE-2020-29599
was published
May 24, 2022
XML injection in Crafter CMS
High
CVE-2017-15683
was published
for
org.craftercms:crafter-core
(Maven)
May 24, 2022
yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an...
Critical
Unreviewed
CVE-2020-25216
was published
May 24, 2022
A buffer overflow was addressed with improved size validation. This issue is fixed in iOS 13.3.1...
Moderate
Unreviewed
CVE-2020-3846
was published
May 24, 2022
An issue was discovered in ezXML 0.8.3 through 0.8.6. The ezxml_parse_* functions mishandle XML...
Moderate
Unreviewed
CVE-2019-20201
was published
May 24, 2022
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19032
was published
May 24, 2022
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is:...
High
Unreviewed
CVE-2019-19031
was published
May 24, 2022
Modoboa is vulnerable to an XML External Entity Injection (XXE)
High
CVE-2019-19702
was published
for
modoboa-dmarc
(pip)
May 24, 2022
Magento 2 Community Edition XML Injection
Critical
CVE-2019-8158
was published
for
magento/community-edition
(Composer)
May 24, 2022
ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via...
High
Unreviewed
CVE-2019-17323
was published
May 24, 2022
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka...
High
Unreviewed
CVE-2019-18213
was published
May 24, 2022
Due to missing input validation, SAP Financial Consolidation, before versions 10.0 and 10.1,...
Moderate
Unreviewed
CVE-2019-0370
was published
May 24, 2022
IBM Security Directory Server 6.4.0 does not properly neutralize special elements that are used...
High
Unreviewed
CVE-2019-4539
was published
May 24, 2022
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if...
Critical
Unreviewed
CVE-2019-16941
was published
May 24, 2022
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is...
Critical
Unreviewed
CVE-2019-14277
was published
May 24, 2022
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a...
High
Unreviewed
CVE-2019-12787
was published
May 24, 2022
The Zoom Client for Meetings (for Android, iOS, Linux, MacOS, and Windows) before version 5.10.0...
High
Unreviewed
CVE-2022-22784
was published
May 19, 2022
XML Injection in Apache Solr
Moderate
CVE-2013-6408
was published
for
org.apache.solr:solr-core
(Maven)
May 17, 2022
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
High
CVE-2013-4221
was published
for
org.restlet.jse:org.restlet
(Maven)
May 17, 2022
IBM BigFix Remote Control before 9.1.3 allows remote attackers to conduct XML injection attacks...
Moderate
Unreviewed
CVE-2016-2932
was published
May 17, 2022
In Ambari 2.4.x (before 2.4.3) and Ambari 2.5.0, an authorized user of the Ambari Hive View may...
High
Unreviewed
CVE-2017-5654
was published
May 17, 2022
Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks...
High
Unreviewed
CVE-2015-3932
was published
May 17, 2022
Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping...
High
Unreviewed
CVE-2015-3931
was published
May 17, 2022
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection...
Critical
Unreviewed
CVE-2013-7429
was published
May 17, 2022
ProTip!
Advisories are also available from the
GraphQL API