Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Unclassified MEDIUM 5.5
CVE-2026-6807

A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposur…

Mitigation only
Fix from $1,600 2026-04-28
Lxml HIGH 7.5
CVE-2026-41066

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.0, using either of the two parsers in the default configuration (w…

Fix: 6.1.0+
Fix from $1,950 2026-04-24
Openremote HIGH 7.6
CVE-2026-40882

OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML withou…

Fix: 1.22.0+
Fix from $1,950 2026-04-22
Jre HIGH 7.5
CVE-2026-22016

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supporte…

Mitigation only
Fix from $1,950 2026-04-21
Api Manager HIGH 7.5
CVE-2024-8010

The component accepts XML input through the publisher without disabling external entity resolution. This allows malicious actors to submit a crafted …

Fix: 3.2.0.397 / 3.2.1.27+
Fix from $1,950 2026-04-16
Api Manager CRITICAL 9.1
CVE-2024-2374

The XML parsers within multiple WSO2 products accept user-supplied XML data without properly configuring to prevent the resolution of external entiti…

Fix: 2.0.0.328 / 2.0.0.348+
Fix from $2,300 2026-04-16
.net HIGH 7.5
CVE-2026-26171

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

Fix: 7.5.6 / 7.6.1+
Fix from $1,950 2026-04-14
Chamilo Lms MEDIUM 6.5
CVE-2026-33737

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With…

Fix: 1.11.38+
Fix from $1,600 2026-04-10
Connext Professional CRITICAL 9.1
CVE-2026-4374

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing …

Fix: 7.3.1.1 / 7.7.0+
Fix from $2,300 2026-04-01
Xml Notepad MEDIUM 6.5
CVE-2026-34401

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, X…

Fix: 2.9.0.21+
Fix from $1,600 2026-03-31
Grav HIGH 7.6
CVE-2026-29924

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager p…

Fix: 1.8.0+
Fix from $1,950 2026-03-30
Inkscape MEDIUM 6.3
CVE-2026-4980

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files vi…

Fix: 1.3+
Fix from $1,600 2026-03-27
Esaml MEDIUM 5.3
CVE-2026-28809

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their con…

Fix: after 4.6.0
Fix from $1,600 2026-03-23
Unclassified HIGH 8.6
CVE-2026-3511

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated atta…

Mitigation only
Fix from $1,950 2026-03-19
Tolgee MEDIUM 6.5
CVE-2026-32251

Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files don…

Fix: 3.166.3+
Fix from $1,600 2026-03-12
Infosphere Information Server HIGH 7.5
CVE-2026-1567

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could all…

Fix: after 11.7.1.6
Fix from $1,950 2026-03-03
Jeesite HIGH 8.1
CVE-2026-3404

A flaw has been found in thinkgem JeeSite up to 5.15.1. Impacted is an unknown function of the file /com/jeesite/common/shiro/cas/CasOutHandler.java …

Fix: after 5.15.1
Fix from $1,950 2026-03-02
Freeflow Core HIGH 7.5
CVE-2026-2252

An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malic…

Fix: 8.1.0+
Fix from $1,950 2026-02-27
Db2 HIGH 8.2
CVE-2025-36247

IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external en…

Fix: after 12.1.3
Fix from $1,950 2026-02-17
Unclassified MEDIUM 6.3
CVE-2026-2536

A vulnerability was determined in opencc JFlow up to 20260129. This affects the function Imp_Done of the file src/main/java/bp/wf/httphandler/WF_Admi…

Mitigation only
Fix from $1,600 2026-02-16
Unclassified MEDIUM 6.2
CVE-2020-37192

MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted X…

No fix yet
Fix from $1,600 2026-02-11
Unclassified HIGH 7.0
CVE-2026-1227

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interact…

Mitigation only
Fix from $1,950 2026-02-11
O2oa MEDIUM 6.3
CVE-2026-2074

A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the compon…

Fix: after 9.0.0
Fix from $1,600 2026-02-07
Asterisk MEDIUM 6.5
CVE-2026-23739

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 20.7-cert9, 20.18.2, 21.12.1, 22.8.2, and 23.2.2, the ast…

Fix: 20.18.2 / 21.12.1+
Fix from $1,600 2026-02-06
Crowd HIGH 7.9
CVE-2026-21569

This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server. This XXE (X…

Fix: 7.1.3+
Fix from $1,950 2026-01-28
Assertj CRITICAL 9.1
CVE-2026-24400

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML…

Fix: 3.27.7+
Fix from $2,300 2026-01-26
Xdocreport CRITICAL 9.8
CVE-2025-65482

An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a craft…

Fix: after 2.0.3
Fix from $2,300 2026-01-20
Unclassified MEDIUM 6.3
CVE-2026-1218

A vulnerability was detected in Bjskzy Zhiyou ERP up to 11.0. Impacted is the function initRCForm of the file RichClientService.class of the componen…

Mitigation only
Fix from $1,600 2026-01-20
Unclassified HIGH 7.5
CVE-2025-14478

The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the …

Mitigation only
Fix from $1,950 2026-01-17
Geonetwork MEDIUM 6.5
CVE-2022-50899

Geonetwork 3.10 through 4.2.0 contains an XML external entity vulnerability in PDF rendering that allows attackers to retrieve arbitrary files from t…

Fix: after 4.2.0
Fix from $1,600 2026-01-13