Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 5.5
CVE-2026-75055
In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE
Fix unknown
MEDIUM 5.5
CVE-2026-75058
In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers
Fix unknown
HIGH 7.7
CVE-2026-69101
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request …
No fix yet
MEDIUM 6.5
CVE-2026-18715
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e…
I
No fix yet
HIGH 8.7
CVE-2026-15803
In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF dat…
No fix yet
MEDIUM 6.3
CVE-2026-16999
Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linki…
No fix yet
MEDIUM 6.1
CVE-2026-73235
FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp b…
No fix yet
MEDIUM 6.5
CVE-2026-58248
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file…
No fix yet
CRITICAL 9.3
CVE-2026-16626
Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server.
This issue affects JasperR…
No fix yet
HIGH 7.5
CVE-2026-65432
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…
Cxf
3.6.12 / 4.1.8+
HIGH 7.1
CVE-2026-70448
Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report f…
No fix yet
CRITICAL 9.8
CVE-2026-10025
IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…
Qradar Security Information And Event Manager
No fix yet
MEDIUM 5.5
CVE-2026-14304
In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…
Accessibility Tools Framework
3.2.0+
MEDIUM 5.5
CVE-2025-36374
IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v…
No fix yet
HIGH 7.5
CVE-2026-54366
CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary f…
No fix yet
HIGH 7.5
CVE-2026-50782
Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp…
No fix yet
HIGH 8.7
CVE-2026-54078
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …
No fix yet
HIGH 8.7
CVE-2026-54079
veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-valid…
No fix yet
MEDIUM 6.5
CVE-2026-54082
veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …
No fix yet
CRITICAL 9.8
CVE-2026-56817
Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina…
Netty
4.1.136 / 4.2.16+
CRITICAL 9.8
CVE-2026-51080
libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.
Libpve Storage Perl
No fix yet
HIGH 7.5
CVE-2026-8396
Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking.
This iss…
No fix yet
CRITICAL 9.6
CVE-2026-48359
Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary…
Experience Manager
after 2020.5.0
HIGH 7.5
CVE-2026-45071
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawle…
Symfony
5.4.52 / 6.4.40+
MEDIUM 5.3
CVE-2026-54470
Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low p…
Unisphere For Powermax
10.3.0.7+
CRITICAL 9.1
CVE-2026-55471
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.Xslt…
Hl7 Fhir Core
6.9.10+
MEDIUM 6.5
CVE-2026-57259
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised…
Pdf Editor
after 2026.1.1.36485
CRITICAL 9.8
CVE-2026-47898
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Ap…
Lucene.net
Mitigation only
CRITICAL 9.1
CVE-2026-13449
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML …
Business Automation Manager
9.5.0+
HIGH 7.1
CVE-2026-44018
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91…
Docling
2.91.0+