GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,798
Maven
5,000+
npm
4,424
NuGet
772
pip
4,192
Pub
12
RubyGems
968
Rust
1,083
Swift
46
Unreviewed advisories
All unreviewed
5,000+
1,177 advisories
Filter by severity
Bio-Formats has an XML External Entity (XXE) vulnerability
Moderate
CVE-2026-22186
was published
for
ome:pom-bio-formats
(Maven)
Jan 7, 2026
A vulnerability in the licensing features of Cisco Identity Services Engine (ISE) and Cisco...
Moderate
Unreviewed
CVE-2026-20029
was published
Jan 7, 2026
Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML...
High
Unreviewed
CVE-2025-36589
was published
Jan 6, 2026
Apache SIS has Improper Restriction of XML External Entity Reference vulnerability
Moderate
CVE-2025-68280
was published
for
org.apache.sis.core:sis-metadata
(Maven)
Jan 5, 2026
KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the...
High
Unreviewed
CVE-2019-25253
was published
Dec 24, 2025
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity ...
High
Unreviewed
CVE-2018-25142
was published
Dec 24, 2025
OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow...
Moderate
Unreviewed
CVE-2024-58335
was published
Dec 24, 2025
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Moderate
CVE-2025-68463
was published
for
biopython
(pip)
Dec 18, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction...
Moderate
Unreviewed
CVE-2025-61823
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction...
High
Unreviewed
CVE-2025-61813
was published
Dec 10, 2025
ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction...
Moderate
Unreviewed
CVE-2025-61821
was published
Dec 10, 2025
Apache Tika has XXE vulnerability
Critical
CVE-2025-66516
was published
for
org.apache.tika:tika-core
(Maven)
Dec 4, 2025
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial...
Critical
Unreviewed
CVE-2025-65868
was published
Dec 3, 2025
Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD...
Moderate
Unreviewed
CVE-2025-66370
was published
Nov 28, 2025
Mustangproject allows exfiltrating files via XXE attacks
Low
CVE-2025-66372
was published
for
org.mustangproject:library
(Maven)
Nov 28, 2025
Peppol-py is vulnerable to XXE attacks due to Saxon configuration
Moderate
CVE-2025-66371
was published
for
peppol_py
(pip)
Nov 28, 2025
GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
High
CVE-2025-58360
was published
for
org.geoserver.web:gs-web-app
(Maven)
Nov 25, 2025
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML...
High
Unreviewed
CVE-2025-63917
was published
Nov 17, 2025
N-central versions < 2025.4 are vulnerable to an XML External Entities injection leading to...
High
Unreviewed
CVE-2025-11700
was published
Nov 12, 2025
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
CVE-2025-64518
was published
for
org.cyclonedx:cyclonedx-core-java
(Maven)
Nov 10, 2025
A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity ...
High
Unreviewed
CVE-2025-63551
was published
Nov 6, 2025
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
Moderate
CVE-2025-10713
was published
for
org.wso2.carbon.mediation:org.wso2.carbon.localentry
(Maven)
Nov 5, 2025
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external...
High
Unreviewed
CVE-2025-12531
was published
Nov 3, 2025
Jenkins JDepend Plugin vulnerable to XML external entity attacks
High
CVE-2025-64134
was published
for
org.jenkins-ci.plugins:jdepend
(Maven)
Oct 29, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper...
Moderate
Unreviewed
CVE-2025-46425
was published
Oct 24, 2025
ProTip!
Advisories are also available from the
GraphQL API