Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
CRITICAL 9.8 CVE-2025-11035 A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.module/ToolBar/ManageWord.asp… Jinher Oa Mitigation only Fix from $2,3002025-09-26 CRITICAL 9.8 CVE-2025-10816 A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?te… Jinher Oa Mitigation only Fix from $2,3002025-09-22 CRITICAL 9.1 CVE-2025-10183 A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate… Mitigation only Fix from $2,3002025-09-09 CRITICAL 9.8 CVE-2025-10092 A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?… Jinher Oa after 1.2 Fix from $2,3002025-09-08 CRITICAL 9.8 CVE-2025-10091 A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHtt… Jinher Oa after 1.2 Fix from $2,3002025-09-08 HIGH 8.7 CVE-2023-7307 Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE)… Mitigation only Fix from $1,9502025-08-27 MEDIUM 5.5 CVE-2025-57704 Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability. Mitigation only Fix from $1,6002025-08-26 HIGH 8.4 CVE-2025-54988EPSS 9% Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out… Tika 3.2.2+ Fix from $1,9502025-08-20 HIGH 8.2 CVE-2025-4044 Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive informatio… Mitigation only Fix from $1,9502025-08-19 MEDIUM 5.5 CVE-2025-40584 A vulnerability has been identified in SIMOTION SCOUT TIA V5.4 (All versions), SIMOTION SCOUT TIA V5.5 (All versions), SIMOTION SCOUT TIA V5.6 (All v… Mitigation only Fix from $1,6002025-08-12 MEDIUM 6.9 CVE-2025-54992 OpenKilda is an open-source OpenFlow controller. Prior to version 1.164.0, an XML external entity (XXE) injection vulnerability was found in OpenKild… Patch available Fix from $1,6002025-08-11 HIGH 7.5 CVE-2025-8355EPSS 7% In Xerox FreeFlow Core version 8.0.4, improper handling of XML input allows injection of external entities. An attacker can craft malicious XML conta… Freeflow Core Mitigation only Fix from $1,9502025-08-08 HIGH 8.6 CVE-2025-54254EPSS 77% Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability t… Experience Manager Forms after 6.5.23.0 Fix from $1,9502025-08-05 MEDIUM 6.5 CVE-2025-36608 Dell SmartFabric OS10 Software, versions prior to 10.6.0.5, contains an Improper Restriction of XML External Entity Reference vulnerability. A low pr… Smartfabric Os10 10.6.0.5+ Fix from $1,6002025-07-30 MEDIUM 6.5 CVE-2025-26400 SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosur… Web Help Desk 12.8.7+ Fix from $1,6002025-07-29 CRITICAL 9.8 CVE-2025-54445EPSS 10% Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This… Magicinfo 9 Server 21.1080.0+ Fix from $2,3002025-07-23 HIGH 8.0 CVE-2025-7766 Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenti… Mitigation only Fix from $1,9502025-07-22 MEDIUM 6.9 CVE-2025-34142 An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint… Mitigation only Fix from $1,6002025-07-22 CRITICAL 9.8 CVE-2025-7823 A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleD… Jinher Oa Mitigation only Fix from $2,3002025-07-19 CRITICAL 9.8 CVE-2025-7824 A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. Th… Jinher Oa Mitigation only Fix from $2,3002025-07-19 MEDIUM 6.5 CVE-2025-52162 agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vuln… Mitigation only Fix from $1,6002025-07-18 MEDIUM 6.9 CVE-2025-53621 DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) inj… Patch available Fix from $1,6002025-07-15 HIGH 8.8 CVE-2025-53689 Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to … Jackrabbit 2.20.17+ Fix from $1,9502025-07-14 CRITICAL 9.8 CVE-2025-7523 A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft… Jinher Oa Mitigation only Fix from $2,3002025-07-13 MEDIUM 5.9 CVE-2025-6438 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML … Mitigation only Fix from $1,6002025-07-11 MEDIUM 6.8 CVE-2025-49544 ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili… Coldfusion Mitigation only Fix from $1,6002025-07-08 CRITICAL 9.3 CVE-2025-49535 ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerabili… Coldfusion Mitigation only Fix from $2,3002025-07-08 MEDIUM 5.8 CVE-2025-49493 Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection. Mitigation only Fix from $1,6002025-06-30 HIGH 7.5 CVE-2025-52888 Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists … Patch available Fix from $1,9502025-06-24 HIGH 7.1 CVE-2025-33121 IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot… Qradar Security Information And Event Manager Mitigation only Fix from $1,9502025-06-19