Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.1 CVE-2025-68493EPSS 37% Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from… Struts 6.1.1+ Fix from $1,9502026-01-11 HIGH 7.1 CVE-2026-22186 Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing componen… Bio Formats after 8.3.0 Fix from $1,9502026-01-07 HIGH 7.1 CVE-2025-36589 Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged … Unisphere For Powermax 9.2.4.19+ Fix from $1,9502026-01-06 MEDIUM 6.5 CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars… Spatial Information System after 1.5 Fix from $1,6002026-01-05 MEDIUM 5.6 CVE-2025-15251 A vulnerability was detected in beecue FastBee up to 2.1. Impacted is the function getRootElement of the file springboot/fastbee-server/sip-server/sr… Mitigation only Fix from $1,6002025-12-30 HIGH 7.5 CVE-2019-25253 KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated… Net Admin No fix yet Fix from $1,9502025-12-24 CRITICAL 9.8 CVE-2018-25142 NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import … Mitigation only Fix from $2,3002025-12-24 MEDIUM 5.0 CVE-2024-58335 OpenXRechnungToolbox through 2024-10-05-3.0.0 before 6c50e89 allows XXE because the disallow-doctype-decl feature is not enabled in visualization/Vis… Patch available Fix from $1,6002025-12-24 MEDIUM 6.8 CVE-2025-61821 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili… Coldfusion Mitigation only Fix from $1,6002025-12-10 MEDIUM 6.2 CVE-2025-61823 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili… Coldfusion Mitigation only Fix from $1,6002025-12-10 HIGH 7.4 CVE-2025-61813 ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili… Coldfusion Mitigation only Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2025-66516EPSS 79% Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a… Tika 3.2.2+ Fix from $2,3002025-12-04 HIGH 7.5 CVE-2025-65868 XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request. Eyoucms No fix yet Fix from $1,9502025-12-03 MEDIUM 5.0 CVE-2025-66370 Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to read and exfiltrate files fr… Patch available Fix from $1,6002025-11-28 MEDIUM 5.0 CVE-2025-66371 Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XML parser could read files fro… Patch available Fix from $1,6002025-11-28 CRITICAL 9.8 CVE-2025-58360 KEVEPSS 65% GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XM… Geoserver 2.25.6 / 2.26.2+ Fix from $2,3002025-11-25 HIGH 7.1 CVE-2025-63917 PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application use… Pdfpatcher after 1.1.3.4663 Fix from $1,9502025-11-17 MEDIUM 6.3 CVE-2025-13209 A weakness has been identified in bestfeng oa_git_free up to 9.5. This affects the function updateWriteBack of the file yimioa-oa9.5\server\c-flow\sr… Mitigation only Fix from $1,6002025-11-15 HIGH 7.5 CVE-2025-11700EPSS 31% N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure N Central 2025.4+ Fix from $1,9502025-11-12 HIGH 7.5 CVE-2025-64518 The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Star… Patch available Fix from $1,9502025-11-10 HIGH 7.5 CVE-2025-63551 A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management S… Metinfo 8.1+ Fix from $1,9502025-11-06 CRITICAL 9.1 CVE-2025-10713 An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML parser. The application parses u… Api Control Plane Mitigation only Fix from $2,3002025-11-05 CRITICAL 9.1 CVE-2025-12531 IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. … Infosphere Information Server after 11.7.1.6 Fix from $2,3002025-11-03 HIGH 7.1 CVE-2025-64134 Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML e… Jdepend after 1.3.1 Fix from $1,9502025-10-29 MEDIUM 6.5 CVE-2025-46425 Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A … Storage Manager 2020+ Fix from $1,6002025-10-24 HIGH 7.5 CVE-2025-6985 The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing… Mitigation only Fix from $1,9502025-10-06 CRITICAL 9.8 CVE-2025-11341 A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.as… Jinher Oa after 2.0 Fix from $2,3002025-10-06 MEDIUM 6.5 CVE-2025-20369 In Splunk Enterprise versions below 9.4.4, 9.3.6, and 9.2.8, and Splunk Cloud Platform versions below 9.3.2411.108, 9.3.2408.118 and 9.2.2406.123, a … Splunk 9.2.8 / 9.2.2406.123+ Fix from $1,6002025-10-01 CRITICAL 9.1 CVE-2025-48006 Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processe… Dataspider Servista after 4.4 Fix from $2,3002025-09-29 CRITICAL 9.8 CVE-2025-11140 A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.r… Zhiyou Erp after 11.0 Fix from $2,3002025-09-29