Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 5.5 CVE-2026-75055 In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE Fix unknown Fix from $4,0002026-08-17 MEDIUM 5.5 CVE-2026-75058 In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers Fix unknown Fix from $4,0002026-08-17 HIGH 7.7 CVE-2026-69101 Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request … No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-18715 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e… I No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-15803 In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF dat… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-16999 Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linki… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-73235 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp b… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-58248 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.3 CVE-2026-16626 Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR… No fix yet Fix from $5,7502026-08-10 HIGH 7.5 CVE-2026-65432 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-70448 Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report f… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-10025 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne… Qradar Security Information And Event Manager No fix yet Fix from $2,3002026-08-05 MEDIUM 5.5 CVE-2026-14304 In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe… Accessibility Tools Framework 3.2.0+ Fix from $1,6002026-08-05 MEDIUM 5.5 CVE-2025-36374 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-54366 CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary f… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-50782 Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp… No fix yet Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-54078 veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an … No fix yet Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-54079 veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-valid… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-54082 veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an … No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-56817 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Fina… Netty 4.1.136 / 4.2.16+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-51080 libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. Libpve Storage Perl No fix yet Fix from $2,3002026-07-17 HIGH 7.5 CVE-2026-8396 Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This iss… No fix yet Fix from $1,9502026-07-17 CRITICAL 9.6 CVE-2026-48359 Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary… Experience Manager after 2020.5.0 Fix from $2,3002026-07-14 HIGH 7.5 CVE-2026-45071 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Crawle… Symfony 5.4.52 / 6.4.40+ Fix from $1,9502026-07-14 MEDIUM 5.3 CVE-2026-54470 Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low p… Unisphere For Powermax 10.3.0.7+ Fix from $1,6002026-07-10 CRITICAL 9.1 CVE-2026-55471 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.Xslt… Hl7 Fhir Core 6.9.10+ Fix from $2,3002026-07-08 MEDIUM 6.5 CVE-2026-57259 The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised… Pdf Editor after 2026.1.1.36485 Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-13449 IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML … Business Automation Manager 9.5.0+ Fix from $2,3002026-06-30 HIGH 7.1 CVE-2026-44018 Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91… Docling 2.91.0+ Fix from $1,9502026-06-26