GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
121
GitHub Actions
56
Go
4,847
Maven
5,000+
npm
5,000+
NuGet
1,131
pip
5,000+
Pub
13
RubyGems
1,158
Rust
1,579
Swift
63
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,513
Rust
20
39 advisories
Filter by severity
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause...
Moderate
Unreviewed
CVE-2026-65124
was published
Sep 22, 2026
WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML...
Moderate
Unreviewed
CVE-2026-89247
was published
Sep 11, 2026
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can...
Moderate
Unreviewed
CVE-2026-24329
was published
Aug 11, 2026
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
fast-xml-builder Comment Value regex can be bypassed
Moderate
CVE-2026-44664
was published
for
fast-xml-builder
(npm)
May 8, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
Moderate
CVE-2026-41650
was published
for
fast-xml-parser
(npm)
Apr 22, 2026
Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in...
Moderate
Unreviewed
CVE-2026-28770
was published
Mar 4, 2026
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System ...
Moderate
Unreviewed
CVE-2026-1554
was published
Feb 4, 2026
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
Moderate
CVE-2025-66034
was published
for
fonttools
(pip)
Dec 1, 2025
A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by...
Moderate
Unreviewed
CVE-2025-12921
was published
Nov 10, 2025
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML...
Moderate
Unreviewed
CVE-2025-7473
was published
Oct 21, 2025
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1...
Moderate
Unreviewed
CVE-2025-60833
was published
Oct 8, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection...
Moderate
Unreviewed
CVE-2025-54251
was published
Sep 9, 2025
XML Injection vulnerability in xmltodict allows Input Data Manipulation.This issue affects...
Moderate
Unreviewed
CVE-2025-9375
was published
Sep 5, 2025
An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 7...
Moderate
Unreviewed
CVE-2025-47184
was published
Aug 21, 2025
An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java...
Moderate
Unreviewed
CVE-2025-25589
was published
Mar 18, 2025
XPath Injection vulnerabilities in the blog and RSS functions of Modern Campus - Omni CMS 2023.1...
Moderate
Unreviewed
CVE-2023-35858
was published
Jun 13, 2024
An issue was discovered in Logpoint before 7.4.0. A path injection vulnerability is seen while...
Moderate
Unreviewed
CVE-2024-33858
was published
May 7, 2024
Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This...
Moderate
Unreviewed
CVE-2023-32173
was published
May 3, 2024
A vulnerability, which was classified as problematic, was found in Netentsec NS-ASG Application...
Moderate
Unreviewed
CVE-2024-2648
was published
Mar 20, 2024
A vulnerability classified as problematic has been found in Netentsec NS-ASG Application Security...
Moderate
Unreviewed
CVE-2024-2645
was published
Mar 20, 2024
codehaus-plexus vulnerable to XML injection
Moderate
CVE-2022-4245
was published
for
org.codehaus.plexus:plexus-utils
(Maven)
Sep 25, 2023
Magento Open Source allows XML Injection
Moderate
CVE-2023-29289
was published
for
magento/community-edition
(Composer)
Jun 15, 2023
ProTip!
Advisories are also available from the
GraphQL API