Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Struts HIGH 8.1
CVE-2025-68493EPSS 37%

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from…

Fix: 6.1.1+
Fix from $1,950 2026-01-11
Bio Formats HIGH 7.1
CVE-2026-22186

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing componen…

Fix: after 8.3.0
Fix from $1,950 2026-01-07
Unisphere For Powermax HIGH 7.1
CVE-2025-36589

Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged …

Fix: 9.2.4.19+
Fix from $1,950 2026-01-06
Spatial Information System MEDIUM 6.5
CVE-2025-68280

Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars…

Fix: after 1.5
Fix from $1,600 2026-01-05
Unclassified MEDIUM 5.6
CVE-2025-15251

A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/sr…

Mitigation only
Fix from $1,600 2025-12-30
Net Admin HIGH 7.5
CVE-2019-25253

KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated…

No fix yet
Fix from $1,950 2025-12-24
Unclassified CRITICAL 9.8
CVE-2018-25142

NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import …

Mitigation only
Fix from $2,300 2025-12-24
Unclassified MEDIUM 5.0
CVE-2024-58335

OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/Vis…

Patch available
Fix from $1,600 2025-12-24
Coldfusion MEDIUM 6.8
CVE-2025-61821

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-12-10
Coldfusion MEDIUM 6.2
CVE-2025-61823

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-12-10
Coldfusion HIGH 7.4
CVE-2025-61813

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,950 2025-12-10
Tika CRITICAL 9.8
CVE-2025-66516EPSS 79%

Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…

Fix: 3.2.2+
Fix from $2,300 2025-12-04
Eyoucms HIGH 7.5
CVE-2025-65868

XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.

No fix yet
Fix from $1,950 2025-12-03
Unclassified MEDIUM 5.0
CVE-2025-66370

Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files fr…

Patch available
Fix from $1,600 2025-11-28
Unclassified MEDIUM 5.0
CVE-2025-66371

Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files fro…

Patch available
Fix from $1,600 2025-11-28
Geoserver CRITICAL 9.8
CVE-2025-58360 KEVEPSS 65%

GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XM…

Fix: 2.25.6 / 2.26.2+
Fix from $2,300 2025-11-25
Pdfpatcher HIGH 7.1
CVE-2025-63917

PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application use…

Fix: after 1.1.3.4663
Fix from $1,950 2025-11-17
Unclassified MEDIUM 6.3
CVE-2025-13209

A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\sr…

Mitigation only
Fix from $1,600 2025-11-15
N Central HIGH 7.5
CVE-2025-11700EPSS 31%

N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure

Fix: 2025.4+
Fix from $1,950 2025-11-12
Unclassified HIGH 7.5
CVE-2025-64518

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Star…

Patch available
Fix from $1,950 2025-11-10
Metinfo HIGH 7.5
CVE-2025-63551

A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management S…

Fix: 8.1+
Fix from $1,950 2025-11-06
Api Control Plane CRITICAL 9.1
CVE-2025-10713

An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u…

Mitigation only
Fix from $2,300 2025-11-05
Infosphere Information Server CRITICAL 9.1
CVE-2025-12531

IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. …

Fix: after 11.7.1.6
Fix from $2,300 2025-11-03
Jdepend HIGH 7.1
CVE-2025-64134

Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML e…

Fix: after 1.3.1
Fix from $1,950 2025-10-29
Storage Manager MEDIUM 6.5
CVE-2025-46425

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A …

Fix: 2020+
Fix from $1,600 2025-10-24
Unclassified HIGH 7.5
CVE-2025-6985

The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing…

Mitigation only
Fix from $1,950 2025-10-06
Jinher Oa CRITICAL 9.8
CVE-2025-11341

A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.as…

Fix: after 2.0
Fix from $2,300 2025-10-06
Splunk MEDIUM 6.5
CVE-2025-20369

In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a …

Fix: 9.2.8 / 9.2.2406.123+
Fix from $1,600 2025-10-01
Dataspider Servista CRITICAL 9.1
CVE-2025-48006

Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processe…

Fix: after 4.4
Fix from $2,300 2025-09-29
Zhiyou Erp CRITICAL 9.8
CVE-2025-11140

A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.r…

Fix: after 11.0
Fix from $2,300 2025-09-29