GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,845
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,578
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
146 advisories
Filter by severity
An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while...
Moderate
Unreviewed
CVE-2024-33858
was published
May 7, 2024
Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This...
Moderate
Unreviewed
CVE-2023-32173
was published
May 3, 2024
Parallels Desktop Toolgate XML Injection Local Privilege Escalation Vulnerability. This...
High
Unreviewed
CVE-2023-27328
was published
May 3, 2024
A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application...
Moderate
Unreviewed
CVE-2024-2648
was published
Mar 20, 2024
A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security...
Moderate
Unreviewed
CVE-2024-2645
was published
Mar 20, 2024
A XSLT Server Side injection vulnerability in the Import Jobs function of FireBear Improved...
Critical
Unreviewed
CVE-2024-25413
was published
Feb 16, 2024
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize...
High
Unreviewed
CVE-2023-46214
was published
Nov 16, 2023
IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE)...
Critical
Unreviewed
CVE-2022-32755
was published
Oct 14, 2023
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum...
Critical
Unreviewed
CVE-2023-43187
was published
Sep 27, 2023
codehaus-plexus vulnerable to XML injection
Moderate
CVE-2022-4245
was published
for
org.codehaus.plexus:plexus-utils
(Maven)
Sep 25, 2023
ReportLab vulnerable to remote code execution via paraparser
Critical
CVE-2019-19450
was published
for
reportlab
(pip)
Sep 20, 2023
In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible...
High
Unreviewed
CVE-2023-40612
was published
Aug 23, 2023
Apache Ivy External Entity Reference vulnerability
High
CVE-2022-46751
was published
for
org.apache.ivy:ivy
(Maven)
Aug 21, 2023
Magento Open Source allows XML Injection
Low
CVE-2023-38207
was published
for
magento/community-edition
(Composer)
Aug 9, 2023
Magento Open Source allows XML Injection
Moderate
CVE-2023-29289
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
Umbraco CMS 7.12.4 allows Remote Code Execution by authenticated administrators via msxsl:script...
High
Unreviewed
CVE-2019-25137
was published
May 18, 2023
Magento Open Source allows XML Injection
High
CVE-2023-22247
was published
for
magento/community-edition
(Composer)
Mar 27, 2023
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0...
High
Unreviewed
CVE-2023-27253
was published
Mar 18, 2023
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox....
Critical
Unreviewed
CVE-2021-4140
was published
Dec 22, 2022
Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High
CVE-2022-46464
was published
for
concrete5/concrete5
(Composer)
Dec 6, 2022
•
withdrawn
XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to...
High
Unreviewed
CVE-2022-35259
was published
Dec 6, 2022
XML injection in the Intel(R) Quartus Prime Pro and Standard edition software may allow an...
High
Unreviewed
CVE-2022-27233
was published
Nov 11, 2022
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of...
Moderate
Unreviewed
CVE-2022-22243
was published
Oct 18, 2022
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an...
Moderate
Unreviewed
CVE-2022-22244
was published
Oct 18, 2022
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2022-34253
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
ProTip!
Advisories are also available from the
GraphQL API