GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,189
Erlang
31
GitHub Actions
19
Go
1,985
Maven
5,000+
npm
3,701
NuGet
657
pip
3,326
Pub
11
RubyGems
882
Rust
836
Swift
35
Unreviewed advisories
All unreviewed
5,000+
26 advisories
Filter by severity
robrichards/xmlseclibs XPath injection
High
GHSA-2g98-f9jv-w8c5
was published
for
robrichards/xmlseclibs
(Composer)
May 20, 2024
veraPDF has potential XSLT injection vulnerability when using policy files
High
CVE-2024-28109
was published
for
org.verapdf:core
(Maven)
May 20, 2024
codehaus-plexus vulnerable to XML injection
Moderate
CVE-2022-4245
was published
for
org.codehaus.plexus:plexus-utils
(Maven)
Sep 25, 2023
ReportLab vulnerable to remote code execution via paraparser
Critical
CVE-2019-19450
was published
for
reportlab
(pip)
Sep 20, 2023
Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks
High
CVE-2022-46464
was published
for
concrete5/concrete5
(Composer)
Dec 6, 2022
•
withdrawn
Magento XML Injection vulnerability in the Widgets Module
Critical
CVE-2022-34253
was published
for
magento/community-edition
(Composer)
Aug 17, 2022
Magento XML injection in the Widgets module
Critical
CVE-2021-21019
was published
for
magento/community-edition
(Composer)
May 24, 2022
Magento XPath Injection
Critical
CVE-2021-21025
was published
for
magento/community-edition
(Composer)
May 24, 2022
XML injection in Crafter CMS
High
CVE-2017-15683
was published
for
org.craftercms:crafter-core
(Maven)
May 24, 2022
Modoboa is vulnerable to an XML External Entity Injection (XXE)
High
CVE-2019-19702
was published
for
modoboa-dmarc
(pip)
May 24, 2022
Magento 2 Community Edition XML Injection
Critical
CVE-2019-8158
was published
for
magento/community-edition
(Composer)
May 24, 2022
XML Injection in Apache Solr
Moderate
CVE-2013-6408
was published
for
org.apache.solr:solr-core
(Maven)
May 17, 2022
Restlet is vulnerable to Arbitrary Java Code Execution via crafted XML
High
CVE-2013-4221
was published
for
org.restlet.jse:org.restlet
(Maven)
May 17, 2022
XML Injection in Xerces Java affects Nokogiri
Moderate
GHSA-xxx9-3xcr-gjj3
was published
for
nokogiri
(RubyGems)
Apr 11, 2022
XML Injection in Crafter CMS Crafter Studio 3.0.1
High
CVE-2017-15685
was published
for
org.craftercms:crafter-studio
(Maven)
Feb 9, 2022
Infinite Loop in Apache Xerces Java
Moderate
CVE-2022-23437
was published
for
xerces:xercesImpl
(Maven)
Jan 27, 2022
XML External Entity Injection in PyWPS
High
CVE-2021-39371
was published
for
pywps
(pip)
Sep 2, 2021
Layout XML Arbitrary Code Fix
High
CVE-2021-32758
was published
for
openmage/magento-lts
(Composer)
Aug 30, 2021
Duplicate Advisory: XML Injection in petl
Critical
GHSA-69q2-p9xp-739v
was published
for
petl
(pip)
Apr 20, 2021
•
withdrawn
XXE in PHPSpreadsheet due to encoding issue
High
CVE-2018-19277
was published
for
phpoffice/phpspreadsheet
(Composer)
Nov 20, 2019
XML Injection in python-libnmap
High
CVE-2019-1010017
was published
for
python-libnmap
(pip)
Jul 18, 2019
Apache Struts REST Plugin can potentially allow a DoS attack
High
CVE-2018-1327
was published
for
org.apache.struts:struts2-rest-plugin
(Maven)
Oct 16, 2018
Dom4j contains a XML Injection vulnerability
High
CVE-2018-1000632
was published
for
dom4j:dom4j
(Maven)
Oct 16, 2018
Ruby-saml allows attackers to perform XML signature wrapping attacks
High
CVE-2016-5697
was published
for
ruby-saml
(RubyGems)
Aug 21, 2018
ProTip!
Advisories are also available from the
GraphQL API