GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,239
Erlang
31
GitHub Actions
21
Go
2,007
Maven
5,000+
npm
3,716
NuGet
662
pip
3,388
Pub
11
RubyGems
885
Rust
851
Swift
36
Unreviewed advisories
All unreviewed
5,000+
99 advisories
Filter by severity
XML injection in the Intel(R) Quartus Prime Pro and Standard edition software may allow an...
High
Unreviewed
CVE-2022-27233
was published
Nov 11, 2022
An XPath Injection vulnerability in the J-Web component of Juniper Networks Junos OS allows an...
Moderate
Unreviewed
CVE-2022-22244
was published
Oct 18, 2022
An XPath Injection vulnerability due to Improper Input Validation in the J-Web component of...
Moderate
Unreviewed
CVE-2022-22243
was published
Oct 18, 2022
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2022-34253
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with...
High
Unreviewed
CVE-2022-2458
was published
Aug 11, 2022
CA Clarity 15.8 and below and 15.9.0 contain an insecure XML parsing vulnerability that could...
High
Unreviewed
CVE-2022-33739
was published
Jun 17, 2022
A heap-based buffer overflow vulnerability exists in the XML Decompression...
Critical
Unreviewed
CVE-2021-21829
was published
May 24, 2022
A heap-based buffer overflow vulnerability exists in the XML Decompression LabelDict::Load...
Critical
Unreviewed
CVE-2021-21830
was published
May 24, 2022
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and...
High
Unreviewed
CVE-2020-8479
was published
May 24, 2022
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack...
High
Unreviewed
CVE-2018-1721
was published
May 24, 2022
An issue was discovered in Open Ticket Request System (OTRS) 5.x through 5.0.34, 6.x through 6.0...
Moderate
Unreviewed
CVE-2019-9892
was published
May 24, 2022
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE)...
Critical
Unreviewed
CVE-2021-38948
was published
May 24, 2022
Injection attack caused the denial of service vulnerability in NetIQ Access Manager prior to 5.0...
Moderate
Unreviewed
CVE-2021-22524
was published
May 24, 2022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are...
High
Unreviewed
CVE-2021-36020
was published
May 24, 2022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are...
Critical
Unreviewed
CVE-2021-36022
was published
May 24, 2022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are...
Critical
Unreviewed
CVE-2021-36033
was published
May 24, 2022
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are...
Critical
Unreviewed
CVE-2021-36028
was published
May 24, 2022
OrbiTeam BSCW Classic before 7.4.3 allows exportpdf authenticated remote code execution (RCE) via...
High
Unreviewed
CVE-2021-36359
was published
May 24, 2022
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection,...
Critical
Unreviewed
CVE-2021-37154
was published
May 24, 2022
Vulnerability in OpenGrok (component: Web App). Versions that are affected are 1.6.7 and prior....
High
Unreviewed
CVE-2021-2322
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_decode() performs...
High
Unreviewed
CVE-2021-31598
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs...
Moderate
Unreviewed
CVE-2021-31347
was published
May 24, 2022
An issue was discovered in libezxml.a in ezXML 0.8.6. The function ezxml_parse_str() performs...
Moderate
Unreviewed
CVE-2021-31348
was published
May 24, 2022
Magento XML injection in the Widgets module
Critical
CVE-2021-21019
was published
for
magento/community-edition
(Composer)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API