GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,908
Erlang
39
GitHub Actions
38
Go
2,568
Maven
5,000+
npm
4,240
NuGet
754
pip
4,004
Pub
12
RubyGems
953
Rust
1,042
Swift
45
Unreviewed advisories
All unreviewed
5,000+
507 advisories
Filter by severity
Apache Ivy External Entity Reference vulnerability
High
CVE-2022-46751
was published
for
org.apache.ivy:ivy
(Maven)
Aug 21, 2023
This vulnerability allows remote attackers to disclose sensitive information on affected...
High
Unreviewed
CVE-2022-36969
was published
Mar 29, 2023
IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0
is vulnerable to...
High
Unreviewed
CVE-2023-47160
was published
Feb 19, 2025
IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity...
High
Unreviewed
CVE-2024-49781
was published
Feb 20, 2025
XXE in PHPSpreadsheet due to incomplete fix for previous encoding issue
High
CVE-2019-12331
was published
for
phpoffice/phpexcel
(Composer)
Nov 20, 2019
XXE in PHPSpreadsheet encoding is returned
High
CVE-2024-45048
was published
for
phpoffice/phpexcel
(Composer)
Aug 29, 2024
XXE in PHPSpreadsheet's XLSX reader
High
CVE-2024-45293
was published
for
phpoffice/phpexcel
(Composer)
Oct 7, 2024
XmlScanner bypass leads to XXE
High
CVE-2024-47873
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
XXE in PHPSpreadsheet's XLSX reader
High
CVE-2024-48917
was published
for
phpoffice/phpexcel
(Composer)
Nov 18, 2024
IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE...
High
Unreviewed
CVE-2025-0162
was published
Mar 7, 2025
In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete...
High
Unreviewed
CVE-2018-9375
was published
Jan 18, 2025
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component:...
High
Unreviewed
CVE-2024-21255
was published
Oct 15, 2024
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection...
High
Unreviewed
CVE-2023-24323
was published
Feb 9, 2023
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote...
High
Unreviewed
CVE-2014-2052
was published
May 17, 2022
The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server
High
CVE-2025-31487
was published
for
org.xwiki.contrib.jira:jira-macro-default
(Maven)
Apr 4, 2025
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A...
High
Unreviewed
CVE-2023-23595
was published
Jan 15, 2023
ezsystems/ezplatform-richtext allows access to external entities in XML
High
GHSA-2jqj-5qv2-xvcg
was published
for
ezsystems/ezplatform-richtext
(Composer)
Apr 10, 2025
ibexa/fieldtype-richtext allows access to external entities in XML
High
GHSA-cj3w-g42v-wcj6
was published
for
ibexa/fieldtype-richtext
(Composer)
Apr 10, 2025
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update...
High
Unreviewed
CVE-2016-4264
was published
May 13, 2022
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly...
High
Unreviewed
CVE-2020-14478
was published
Feb 25, 2022
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0...
High
Unreviewed
CVE-2016-4312
was published
May 14, 2022
XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib...
High
Unreviewed
CVE-2017-6055
was published
May 17, 2022
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote...
High
Unreviewed
CVE-2017-8913
was published
May 13, 2022
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved...
High
Unreviewed
CVE-2017-6662
was published
May 14, 2022
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
High
Unreviewed
CVE-2017-1000021
was published
May 14, 2022
ProTip!
Advisories are also available from the
GraphQL API