GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
255 advisories
Filter by severity
Withdrawn Advisory: Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Critical
CVE-2015-3208
was published
for
org.apache.activemq:activemq-client
(Maven)
May 14, 2022
•
withdrawn
XML External Entity Reference in Apache Cayenne
High
CVE-2018-11758
was published
for
org.apache.cayenne:cayenne-parent
(Maven)
May 14, 2022
Apache XML-RPC XXE Vulnerability
High
CVE-2016-5002
was published
for
org.apache.xmlrpc:xmlrpc
(Maven)
May 14, 2022
XML External Entity Reference in weixin-java-tools
Critical
CVE-2019-5312
was published
for
com.github.binarywang:weixin-java-common
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in PMD
High
CVE-2019-7722
was published
for
net.sourceforge.pmd:pmd-core
(Maven)
May 14, 2022
Apache ActiveMQ Apollo XXE Vulnerability
Critical
CVE-2014-3579
was published
for
org.apache.activemq:apollo-project
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in Apache ActiveMQ
Critical
CVE-2014-3600
was published
for
org.apache.activemq:activemq-broker
(Maven)
May 14, 2022
Improper Restriction of XML External Entity Reference in Apache uimaj
Moderate
CVE-2017-15691
was published
for
org.apache.uima:uimafit-core
(Maven)
May 14, 2022
SimpleXML has XML External Entity (XXE) vulnerability
Critical
CVE-2017-1000190
was published
for
org.simpleframework:simple-xml
(Maven)
May 14, 2022
XML External Entity Reference in jbpmmigration
Moderate
CVE-2017-7545
was published
for
org.jbpm.jbpm5:jbpmmigration
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Elasticsearch
Moderate
CVE-2018-17247
was published
for
org.elasticsearch:elasticsearch
(Maven)
May 13, 2022
XXE vulnerability in Jenkins Job Import Plugin
Critical
CVE-2019-1003015
was published
for
org.jenkins-ci.plugins:job-import-plugin
(Maven)
May 13, 2022
Jenkins has XML External Entity (XXE) Vulnerability in Job Configuration via CLI
Moderate
CVE-2015-5319
was published
for
org.jenkins-ci.main:jenkins-core
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apace Derby
Critical
CVE-2015-1832
was published
for
org.apache.derby:derby
(Maven)
May 13, 2022
Apache POI's XLSX2CSV Example XML External Entity (XXE) Vulnerability
Moderate
CVE-2016-5000
was published
for
org.apache.poi:poi-examples
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in iText
High
CVE-2017-9096
was published
for
com.itextpdf:itextpdf
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache Batik
High
CVE-2017-5662
was published
for
org.apache.xmlgraphics:batik
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache CXF JAX-RS
High
CVE-2016-8739
was published
for
org.apache.cxf:cxf-core
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Apache FOP
High
CVE-2017-5661
was published
for
org.apache.xmlgraphics:fop
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Castor
Moderate
CVE-2014-3004
was published
for
org.castor:castor
(Maven)
May 13, 2022
Improper Restriction of XML External Entity Reference in Spring Framework
High
CVE-2014-0225
was published
for
org.springframework:spring-webmvc
(Maven)
May 13, 2022
External Entity Reference in TwelveMonkeys ImageIO
Critical
CVE-2021-23792
was published
for
com.twelvemonkeys.imageio:imageio-metadata
(Maven)
May 7, 2022
XML External Entity Reference in apache jena
Critical
CVE-2022-28890
was published
for
org.apache.jena:jena
(Maven)
May 6, 2022
Multiple components in Apache NiFi do not restrict XML External Entity references
High
CVE-2022-29265
was published
for
org.apache.nifi:nifi
(Maven)
May 1, 2022
Arbitrary file access through XML parsing in org.xwiki.commons:xwiki-commons-xml
Moderate
CVE-2022-24898
was published
for
org.xwiki.commons:xwiki-commons-xml
(Maven)
Apr 28, 2022
ProTip!
Advisories are also available from the
GraphQL API