Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.5
CVE-2026-12975
A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without enabling secure processing featu…
Build Of Apicurio Registry
after 3.2
HIGH 7.5
CVE-2026-44020
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74…
Docling
2.74.0+
MEDIUM 6.5
CVE-2026-56701
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to…
Mitigation only
CRITICAL 9.8
CVE-2026-6653
Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service …
Libxml2
after 2.11.0
MEDIUM 6.3
CVE-2026-12788
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affect…
Mitigation only
MEDIUM 6.7
CVE-2026-48981
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags…
Mitigation only
HIGH 8.2
CVE-2025-58175
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.26.4 and 2.27.3, a GeoServer that uses `E…
Geoserver
2.26.4 / 2.27.3+
CRITICAL 9.8
CVE-2026-49875
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…
Cxf
4.1.7 / 4.2.2+
HIGH 8.2
CVE-2026-40998
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the …
Mitigation only
MEDIUM 5.9
CVE-2026-40991
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the …
Spring Rest Docs
2.0.9 / 3.0.5.1+
HIGH 7.4
CVE-2026-47960
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…
Coldfusion
Mitigation only
MEDIUM 6.5
CVE-2026-8045
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file conten…
Struxureware Data Center Expert
9.1.2+
HIGH 7.7
CVE-2026-2253
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML p…
Vantara Pentaho Data Integration And Analytics
10.2.0.7 / 11.0.0.0+
HIGH 7.1
CVE-2026-3603
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7…
Engineering Lifecycle Management
Patch available
MEDIUM 5.3
CVE-2026-44618
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to …
Cxf
3.6.11 / 4.1.6+
MEDIUM 5.9
CVE-2026-46722
The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can…
Mitigation only
MEDIUM 6.5
CVE-2026-39053
Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to fra…
Mitigation only
MEDIUM 6.5
CVE-2026-44445
ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (X…
Erpnext
15.104.3 / 16.12.0+
HIGH 7.5
CVE-2026-41895
changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS conte…
Changedetection
after 0.54.9
HIGH 7.1
CVE-2026-42212
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Op…
Patch available
HIGH 7.3
CVE-2023-42344
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemist…
Mitigation only
HIGH 7.5
CVE-2023-42346
Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
Mitigation only
HIGH 8.1
CVE-2026-41936
Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticate…
Patch available
CRITICAL 9.8
CVE-2026-38429
OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip fi…
Patch available
CRITICAL 9.1
CVE-2026-40682
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0…
Opennlp
2.5.9+
MEDIUM 5.3
CVE-2026-6501
Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blo…
Mitigation only
HIGH 8.8
CVE-2026-36765
An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbit…
Mitigation only
CRITICAL 9.1
CVE-2025-14543
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Link…
Connext Professional
7.3.1.1 / 7.7.0+
HIGH 7.5
CVE-2024-13971
Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtai…
Lobster Pro
4.12.6-ga+
HIGH 7.5
CVE-2024-39847
Unauthenticated attackers can exploit a weakness in the XML parser functionality of the SOAP endpoints in 4D server. This allows them to obtain read …
Server
No fix yet