GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,662
Maven
5,000+
npm
4,289
NuGet
760
pip
4,069
Pub
12
RubyGems
957
Rust
1,057
Swift
45
Unreviewed advisories
All unreviewed
5,000+
1,160 advisories
Filter by severity
PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML...
High
Unreviewed
CVE-2025-63917
was published
Nov 17, 2025
N-central versions < 2025.4 are vulnerable to an XML External Entities injection leading to...
High
Unreviewed
CVE-2025-11700
was published
Nov 12, 2025
CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
High
CVE-2025-64518
was published
for
org.cyclonedx:cyclonedx-core-java
(Maven)
Nov 10, 2025
A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity ...
High
Unreviewed
CVE-2025-63551
was published
Nov 6, 2025
WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
Moderate
CVE-2025-10713
was published
for
org.wso2.carbon.mediation:org.wso2.carbon.localentry
(Maven)
Nov 5, 2025
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external...
High
Unreviewed
CVE-2025-12531
was published
Nov 3, 2025
Jenkins JDepend Plugin vulnerable to XML external entity attacks
High
CVE-2025-64134
was published
for
org.jenkins-ci.plugins:jdepend
(Maven)
Oct 29, 2025
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper...
Moderate
Unreviewed
CVE-2025-46425
was published
Oct 24, 2025
LangChain Text Splitters is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing
High
CVE-2025-6985
was published
for
langchain-text-splitters
(pip)
Oct 6, 2025
In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions...
Moderate
Unreviewed
CVE-2025-20369
was published
Oct 1, 2025
Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and...
High
Unreviewed
CVE-2025-48006
was published
Sep 29, 2025
A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is...
Moderate
Unreviewed
CVE-2025-11140
was published
Sep 29, 2025
A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of...
Moderate
Unreviewed
CVE-2025-11035
was published
Sep 26, 2025
A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file ...
Moderate
Unreviewed
CVE-2025-10816
was published
Sep 23, 2025
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect...
Critical
Unreviewed
CVE-2025-10183
was published
Sep 9, 2025
A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the...
Moderate
Unreviewed
CVE-2025-10091
was published
Sep 8, 2025
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file ...
Moderate
Unreviewed
CVE-2025-10092
was published
Sep 8, 2025
Langchain Community Vulnerable to XML External Entity (XXE) Attacks
High
CVE-2025-6984
was published
for
langchain-community
(pip)
Sep 4, 2025
Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language...
High
Unreviewed
CVE-2023-7307
was published
Aug 28, 2025
Agiloft Release 28 contains an XML External Entities vulnerability in any table that allows ...
Low
Unreviewed
CVE-2025-35112
was published
Aug 27, 2025
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity...
Moderate
Unreviewed
CVE-2025-57704
was published
Aug 26, 2025
Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
Critical
CVE-2025-54988
was published
for
org.apache.tika:tika-parser-pdf-module
(Maven)
Aug 20, 2025
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for...
High
Unreviewed
CVE-2025-4044
was published
Aug 19, 2025
Dell CloudLink, versions 8.0 through 8.1.1, contains an Improper Restriction of XML External...
Moderate
Unreviewed
CVE-2025-26484
was published
Aug 14, 2025
A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA...
Moderate
Unreviewed
CVE-2025-40584
was published
Aug 12, 2025
ProTip!
Advisories are also available from the
GraphQL API