Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Jinher Oa CRITICAL 9.8
CVE-2025-11035

A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.asp…

Mitigation only
Fix from $2,300 2025-09-26
Jinher Oa CRITICAL 9.8
CVE-2025-10816

A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?te…

Mitigation only
Fix from $2,300 2025-09-22
Unclassified CRITICAL 9.1
CVE-2025-10183

A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate…

Mitigation only
Fix from $2,300 2025-09-09
Jinher Oa CRITICAL 9.8
CVE-2025-10092

A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?…

Fix: after 1.2
Fix from $2,300 2025-09-08
Jinher Oa CRITICAL 9.8
CVE-2025-10091

A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHtt…

Fix: after 1.2
Fix from $2,300 2025-09-08
Unclassified HIGH 8.7
CVE-2023-7307

Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE)…

Mitigation only
Fix from $1,950 2025-08-27
Unclassified MEDIUM 5.5
CVE-2025-57704

Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.

Mitigation only
Fix from $1,600 2025-08-26
Tika HIGH 8.4
CVE-2025-54988EPSS 9%

Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…

Fix: 3.2.2+
Fix from $1,950 2025-08-20
Unclassified HIGH 8.2
CVE-2025-4044

Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive informatio…

Mitigation only
Fix from $1,950 2025-08-19
Unclassified MEDIUM 5.5
CVE-2025-40584

A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All v…

Mitigation only
Fix from $1,600 2025-08-12
Unclassified MEDIUM 6.9
CVE-2025-54992

OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKild…

Patch available
Fix from $1,600 2025-08-11
Freeflow Core HIGH 7.5
CVE-2025-8355EPSS 7%

In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML conta…

Mitigation only
Fix from $1,950 2025-08-08
Experience Manager Forms HIGH 8.6
CVE-2025-54254EPSS 77%

Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t…

Fix: after 6.5.23.0
Fix from $1,950 2025-08-05
Smartfabric Os10 MEDIUM 6.5
CVE-2025-36608

Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low pr…

Fix: 10.6.0.5+
Fix from $1,600 2025-07-30
Web Help Desk MEDIUM 6.5
CVE-2025-26400

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosur…

Fix: 12.8.7+
Fix from $1,600 2025-07-29
Magicinfo 9 Server CRITICAL 9.8
CVE-2025-54445EPSS 10%

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This…

Fix: 21.1080.0+
Fix from $2,300 2025-07-23
Unclassified HIGH 8.0
CVE-2025-7766

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenti…

Mitigation only
Fix from $1,950 2025-07-22
Unclassified MEDIUM 6.9
CVE-2025-34142

An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint…

Mitigation only
Fix from $1,600 2025-07-22
Jinher Oa CRITICAL 9.8
CVE-2025-7823

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleD…

Mitigation only
Fix from $2,300 2025-07-19
Jinher Oa CRITICAL 9.8
CVE-2025-7824

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. Th…

Mitigation only
Fix from $2,300 2025-07-19
Unclassified MEDIUM 6.5
CVE-2025-52162

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vuln…

Mitigation only
Fix from $1,600 2025-07-18
Unclassified MEDIUM 6.9
CVE-2025-53621

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) inj…

Patch available
Fix from $1,600 2025-07-15
Jackrabbit HIGH 8.8
CVE-2025-53689

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to …

Fix: 2.20.17+
Fix from $1,950 2025-07-14
Jinher Oa CRITICAL 9.8
CVE-2025-7523

A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft…

Mitigation only
Fix from $2,300 2025-07-13
Unclassified MEDIUM 5.9
CVE-2025-6438

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML …

Mitigation only
Fix from $1,600 2025-07-11
Coldfusion MEDIUM 6.8
CVE-2025-49544

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $1,600 2025-07-08
Coldfusion CRITICAL 9.3
CVE-2025-49535

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili…

Mitigation only
Fix from $2,300 2025-07-08
Unclassified MEDIUM 5.8
CVE-2025-49493

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

Mitigation only
Fix from $1,600 2025-06-30
Unclassified HIGH 7.5
CVE-2025-52888

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists …

Patch available
Fix from $1,950 2025-06-24
Qradar Security Information And Event Manager HIGH 7.1
CVE-2025-33121

IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot…

Mitigation only
Fix from $1,950 2025-06-19