Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Webmethods Integration HIGH 8.8
CVE-2025-36049

IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2025-06-18
Unclassified HIGH 7.5
CVE-2025-44044

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing mal…

Mitigation only
Fix from $1,950 2025-06-10
Geotools CRITICAL 9.1
CVE-2025-30220EPSS 57%

GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent…

Fix: 2.25.7 / 2.26.3+
Fix from $2,300 2025-06-10
Geoserver HIGH 8.2
CVE-2024-34711

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …

Fix: 2.25.0+
Fix from $1,950 2025-06-10
Unclassified CRITICAL 9.1
CVE-2025-31039

Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue af…

Mitigation only
Fix from $2,300 2025-06-09
Feng Office HIGH 8.1
CVE-2025-5877

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functi…

No fix yet
Fix from $1,950 2025-06-09
Unclassified HIGH 8.7
CVE-2025-48882

PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data usi…

Patch available
Fix from $1,950 2025-05-30
Unclassified MEDIUM 6.8
CVE-2025-4338

Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could …

Mitigation only
Fix from $1,600 2025-05-22
Jgit MEDIUM 5.3
CVE-2025-4949

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement t…

Fix: 5.13.4 / 6.10.1.202505221210+
Fix from $1,600 2025-05-21
Unclassified HIGH 8.7
CVE-2025-27523

XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Dev…

Mitigation only
Fix from $1,950 2025-05-15
Unclassified CRITICAL 9.3
CVE-2025-4641

Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML par…

Patch available
Fix from $2,300 2025-05-14
Unclassified HIGH 8.8
CVE-2025-4639

CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Pee…

Patch available
Fix from $1,950 2025-05-14
Unclassified MEDIUM 6.1
CVE-2025-47778

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin u…

Patch available
Fix from $1,600 2025-05-14
Polarion Alm MEDIUM 6.5
CVE-2024-51445

A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XM…

Fix: 2404.4+
Fix from $1,600 2025-05-13
Supplier Relationship Management HIGH 7.5
CVE-2025-30018

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi…

Mitigation only
Fix from $1,950 2025-05-13
Sysaid HIGH 7.5
CVE-2025-2775 KEVEPSS 43%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…

Fix: after 23.3.40
Fix from $1,950 2025-05-07
Sysaid CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…

Fix: after 23.3.40
Fix from $2,300 2025-05-07
Sysaid CRITICAL 9.8
CVE-2025-2777EPSS 72%

SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,…

Fix: after 23.3.40
Fix from $2,300 2025-05-07
Storage Manager HIGH 8.1
CVE-2025-22478

Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An…

Mitigation only
Fix from $1,950 2025-05-06
Langroid CRITICAL 9.1
CVE-2025-46726

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage…

Fix: 0.53.4+
Fix from $2,300 2025-05-05
Api Manager CRITICAL 9.1
CVE-2025-2905

Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (…

Fix: after 2.0.0
Fix from $2,300 2025-05-05
Mailessentials MEDIUM 6.5
CVE-2025-34490

GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H…

Fix: 21.8+
Fix from $1,600 2025-04-28
Unclassified MEDIUM 5.0
CVE-2025-2070

An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visite…

Mitigation only
Fix from $1,600 2025-04-25
Unclassified HIGH 7.5
CVE-2025-31497

TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversio…

Mitigation only
Fix from $1,950 2025-04-15
Unclassified HIGH 8.6
CVE-2025-32406

An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse…

Mitigation only
Fix from $1,950 2025-04-08
Unclassified MEDIUM 6.6
CVE-2025-32138

Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue af…

Mitigation only
Fix from $1,600 2025-04-04
Youkefu CRITICAL 9.8
CVE-2025-3241

A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/m…

No fix yet
Fix from $2,300 2025-04-04
Unclassified HIGH 7.7
CVE-2025-31487

The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, an…

Patch available
Fix from $1,950 2025-04-03
Css Validator MEDIUM 6.5
CVE-2025-1781

There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side …

Fix: 20250226+
Fix from $1,600 2025-03-28
Goland MEDIUM 5.3
CVE-2025-29932

In JetBrains GoLand before 2025.1 an XXE during debugging was possible

Fix: 2025.1+
Fix from $1,600 2025-03-25