GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
114
GitHub Actions
55
Go
4,636
Maven
5,000+
npm
5,000+
NuGet
1,104
pip
5,000+
Pub
13
RubyGems
1,150
Rust
1,529
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
1,271 advisories
Filter by severity
A flaw was found in RESTEasy's SourceProvider. This vulnerability allows an unauthenticated...
High
Unreviewed
CVE-2026-17615
was published
Aug 31, 2026
YaCy Search Server through 1.941 contains an XML external entity injection vulnerability in SVG,...
High
Unreviewed
CVE-2026-82880
was published
Aug 31, 2026
MapFish Print has XXE that allows reading arbitrary files of certain types
High
CVE-2026-55848
was published
for
org.mapfish.print:print-lib
(Maven)
Aug 28, 2026
A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an...
High
Unreviewed
CVE-2026-20320
was published
Aug 19, 2026
Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML...
Moderate
Unreviewed
CVE-2026-67268
was published
Aug 19, 2026
Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML...
Moderate
Unreviewed
CVE-2026-70423
was published
Aug 19, 2026
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
Moderate
Unreviewed
CVE-2026-75055
was published
Aug 17, 2026
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Moderate
Unreviewed
CVE-2026-75058
was published
Aug 17, 2026
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows...
High
Unreviewed
CVE-2026-69101
was published
Aug 14, 2026
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive...
Moderate
Unreviewed
CVE-2026-18715
was published
Aug 13, 2026
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE)...
High
Unreviewed
CVE-2026-15803
was published
Aug 12, 2026
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP...
Moderate
Unreviewed
CVE-2026-16999
was published
Aug 12, 2026
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged...
Moderate
Unreviewed
CVE-2026-58248
was published
Aug 11, 2026
Improper restriction of XML external entity reference vulnerability (unauthenticated) in...
Critical
Unreviewed
CVE-2026-16626
was published
Aug 10, 2026
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs...
High
Unreviewed
CVE-2026-65432
was published
Aug 6, 2026
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML...
High
Unreviewed
CVE-2026-70448
was published
Aug 5, 2026
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML...
High
Unreviewed
CVE-2026-10025
was published
Aug 5, 2026
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code...
Moderate
Unreviewed
CVE-2026-14304
was published
Aug 5, 2026
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when...
Moderate
Unreviewed
CVE-2025-36374
was published
Jul 30, 2026
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows...
High
Unreviewed
CVE-2026-54366
was published
Jul 30, 2026
Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web...
High
Unreviewed
CVE-2026-50782
was published
Jul 29, 2026
veraPDF-validatio: Use of Default `DocumentBuilderFactory` leads to XXE When Processing Untrusted PDFs
Moderate
CVE-2026-54082
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
veraPDF Validation XXE via Rich Text
High
CVE-2026-54078
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
veraPDF Validation XXE via XFA
High
CVE-2026-54079
was published
for
org.verapdf:validation-model
(Maven)
Jul 29, 2026
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling...
Moderate
Unreviewed
CVE-2026-57917
was published
Jul 27, 2026
ProTip!
Advisories are also available from the
GraphQL API