GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
Filter advisories
GitHub reviewed advisories
Unreviewed advisories
Malware advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
109
GitHub Actions
55
Go
4,556
Maven
5,000+
npm
5,000+
NuGet
1,103
pip
5,000+
Pub
13
RubyGems
1,146
Rust
1,518
Swift
62
Unreviewed advisories
All unreviewed
5,000+
Malware advisories
All malware
5,000+
Composer
2
Go
18
Maven
2
npm
5,000+
NuGet
264
pip
5,000+
RubyGems
3,510
Rust
19
135 advisories
Filter by severity
A flaw was found in wildfly-core. A remote user authenticated as an administrative user can...
Moderate
Unreviewed
CVE-2026-24329
was published
Aug 11, 2026
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction...
Low
Unreviewed
CVE-2026-15037
was published
Jul 23, 2026
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
Moderate
CVE-2026-59728
was published
for
@astrojs/rss
(npm)
Jul 20, 2026
guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDATA Terminator
Moderate
CVE-2026-53723
was published
for
guzzlehttp/guzzle-services
(Composer)
Jun 11, 2026
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote...
High
Unreviewed
CVE-2026-11169
was published
Jun 5, 2026
samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Assertions
High
CVE-2026-46490
was published
for
samlify
(npm)
May 21, 2026
fast-xml-builder allows attribute values with unwanted quotes to bypass malicious or unwanted attributes
High
CVE-2026-44665
was published
for
fast-xml-builder
(npm)
May 8, 2026
fast-xml-builder Comment Value regex can be bypassed
Moderate
CVE-2026-44664
was published
for
fast-xml-builder
(npm)
May 8, 2026
Kirby has XML injection in its XML creator toolkit
Moderate
CVE-2026-32870
was published
for
getkirby/cms
(Composer)
Apr 23, 2026
xmldom has XML injection through unvalidated DocumentType serialization
High
CVE-2026-41674
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated processing instruction serialization
High
CVE-2026-41675
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
xmldom has XML node injection through unvalidated comment serialization
High
CVE-2026-41672
was published
for
@xmldom/xmldom
(npm)
Apr 22, 2026
fast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped Delimiters
Moderate
CVE-2026-41650
was published
for
fast-xml-parser
(npm)
Apr 22, 2026
xmldom: XML injection via unsafe CDATA serialization allows attacker-controlled markup insertion
High
CVE-2026-34601
was published
for
@xmldom/xmldom
(npm)
Apr 1, 2026
Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in...
Moderate
Unreviewed
CVE-2026-28770
was published
Mar 4, 2026
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System ...
Moderate
Unreviewed
CVE-2026-1554
was published
Feb 4, 2026
Wondershare FamiSafe 1.0 contains an unquoted service path vulnerability in the FSService that...
High
Unreviewed
CVE-2022-50902
was published
Jan 14, 2026
An XPath Injection vulnerability in WatchGuard Fireware OS may allow a remote unauthenticated...
High
Unreviewed
CVE-2025-1545
was published
Dec 5, 2025
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
Moderate
CVE-2025-66034
was published
for
fonttools
(pip)
Dec 1, 2025
A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by...
Moderate
Unreviewed
CVE-2025-12921
was published
Nov 10, 2025
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML...
Moderate
Unreviewed
CVE-2025-7473
was published
Oct 21, 2025
An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1...
Moderate
Unreviewed
CVE-2025-60833
was published
Oct 8, 2025
MinIO Java Client XML Tag Value Substitution Vulnerability
High
CVE-2025-59952
was published
for
io.minio:minio
(Maven)
Sep 29, 2025
Adobe Experience Manager versions 6.5.23.0 and earlier are affected by an XML Injection...
Moderate
Unreviewed
CVE-2025-54251
was published
Sep 9, 2025
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat.
...
High
Unreviewed
CVE-2025-24404
was published
Sep 9, 2025
ProTip!
Advisories are also available from the
GraphQL API