Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Unclassified MEDIUM 5.5
CVE-2026-75055

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

Fix unknown
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-75058

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

Fix unknown
Fix from $4,000 2026-08-17
Unclassified HIGH 7.7
CVE-2026-69101

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request …

No fix yet
Fix from $4,900 2026-08-14
I MEDIUM 6.5
CVE-2026-18715

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.7
CVE-2026-15803

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF dat…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-16999

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linki…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-73235

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp b…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-16626

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR…

No fix yet
Fix from $5,750 2026-08-10
Cxf HIGH 7.5
CVE-2026-65432

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-70448

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report f…

No fix yet
Fix from $1,950 2026-08-05
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Accessibility Tools Framework MEDIUM 5.5
CVE-2026-14304

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…

Fix: 3.2.0+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.5
CVE-2025-36374

IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-54366

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary f…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-50782

Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-54078

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-54079

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-valid…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-54082

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …

No fix yet
Fix from $1,600 2026-07-29
Netty CRITICAL 9.8
CVE-2026-56817

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina…

Fix: 4.1.136 / 4.2.16+
Fix from $2,300 2026-07-21
Libpve Storage Perl CRITICAL 9.8
CVE-2026-51080

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 7.5
CVE-2026-8396

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This iss…

No fix yet
Fix from $1,950 2026-07-17
Experience Manager CRITICAL 9.6
CVE-2026-48359

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…

Fix: after 2020.5.0
Fix from $2,300 2026-07-14
Symfony HIGH 7.5
CVE-2026-45071

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawle…

Fix: 5.4.52 / 6.4.40+
Fix from $1,950 2026-07-14
Unisphere For Powermax MEDIUM 5.3
CVE-2026-54470

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low p…

Fix: 10.3.0.7+
Fix from $1,600 2026-07-10
Hl7 Fhir Core CRITICAL 9.1
CVE-2026-55471

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.Xslt…

Fix: 6.9.10+
Fix from $2,300 2026-07-08
Pdf Editor MEDIUM 6.5
CVE-2026-57259

The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised…

Fix: after 2026.1.1.36485
Fix from $1,600 2026-07-08
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Business Automation Manager CRITICAL 9.1
CVE-2026-13449

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …

Fix: 9.5.0+
Fix from $2,300 2026-06-30
Docling HIGH 7.1
CVE-2026-44018

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91…

Fix: 2.91.0+
Fix from $1,950 2026-06-26