Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Build Of Apicurio Registry HIGH 8.5
CVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing featu…

Fix: after 3.2
Fix from $1,950 2026-06-25
Docling HIGH 7.5
CVE-2026-44020

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74…

Fix: 2.74.0+
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-56701

Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to…

Mitigation only
Fix from $1,600 2026-06-23
Libxml2 CRITICAL 9.8
CVE-2026-6653

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service …

Fix: after 2.11.0
Fix from $2,300 2026-06-22
Unclassified MEDIUM 6.3
CVE-2026-12788

A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affect…

Mitigation only
Fix from $1,600 2026-06-21
Unclassified MEDIUM 6.7
CVE-2026-48981

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags…

Mitigation only
Fix from $1,600 2026-06-18
Geoserver HIGH 8.2
CVE-2025-58175

GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…

Fix: 2.26.4 / 2.27.3+
Fix from $1,950 2026-06-18
Cxf CRITICAL 9.8
CVE-2026-49875

Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…

Fix: 4.1.7 / 4.2.2+
Fix from $2,300 2026-06-12
Unclassified HIGH 8.2
CVE-2026-40998

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the …

Mitigation only
Fix from $1,950 2026-06-11
Spring Rest Docs MEDIUM 5.9
CVE-2026-40991

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the …

Fix: 2.0.9 / 3.0.5.1+
Fix from $1,600 2026-06-10
Coldfusion HIGH 7.4
CVE-2026-47960

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…

Mitigation only
Fix from $1,950 2026-06-09
Struxureware Data Center Expert MEDIUM 6.5
CVE-2026-8045

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file conten…

Fix: 9.1.2+
Fix from $1,600 2026-06-09
Vantara Pentaho Data Integration And Analytics HIGH 7.7
CVE-2026-2253

Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML p…

Fix: 10.2.0.7 / 11.0.0.0+
Fix from $1,950 2026-05-27
Engineering Lifecycle Management HIGH 7.1
CVE-2026-3603

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7…

Patch available
Fix from $1,950 2026-05-26
Cxf MEDIUM 5.3
CVE-2026-44618

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to …

Fix: 3.6.11 / 4.1.6+
Fix from $1,600 2026-05-22
Unclassified MEDIUM 5.9
CVE-2026-46722

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can…

Mitigation only
Fix from $1,600 2026-05-19
Unclassified MEDIUM 6.5
CVE-2026-39053

Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to fra…

Mitigation only
Fix from $1,600 2026-05-15
Erpnext MEDIUM 6.5
CVE-2026-44445

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (X…

Fix: 15.104.3 / 16.12.0+
Fix from $1,600 2026-05-13
Changedetection HIGH 7.5
CVE-2026-41895

changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS conte…

Fix: after 0.54.9
Fix from $1,950 2026-05-12
Unclassified HIGH 7.1
CVE-2026-42212

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Op…

Patch available
Fix from $1,950 2026-05-08
Unclassified HIGH 7.3
CVE-2023-42344

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemist…

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 7.5
CVE-2023-42346

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

Mitigation only
Fix from $1,950 2026-05-08
Unclassified HIGH 8.1
CVE-2026-41936

Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticate…

Patch available
Fix from $1,950 2026-05-06
Unclassified CRITICAL 9.8
CVE-2026-38429

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip fi…

Patch available
Fix from $2,300 2026-05-05
Opennlp CRITICAL 9.1
CVE-2026-40682

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0…

Fix: 2.5.9+
Fix from $2,300 2026-05-04
Unclassified MEDIUM 5.3
CVE-2026-6501

Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blo…

Mitigation only
Fix from $1,600 2026-05-04
Unclassified HIGH 8.8
CVE-2026-36765

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbit…

Mitigation only
Fix from $1,950 2026-04-30
Connext Professional CRITICAL 9.1
CVE-2025-14543

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Link…

Fix: 7.3.1.1 / 7.7.0+
Fix from $2,300 2026-04-30
Lobster Pro HIGH 7.5
CVE-2024-13971

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtai…

Fix: 4.12.6-ga+
Fix from $1,950 2026-04-30
Server HIGH 7.5
CVE-2024-39847

Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read …

No fix yet
Fix from $1,950 2026-04-30