Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-36049
IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15
is vulnerable to an XML external entity injection (XXE) attack when processing XML d…
Webmethods Integration
Mitigation only
HIGH 7.5
CVE-2025-44044
Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing mal…
Mitigation only
CRITICAL 9.1
CVE-2025-30220EPSS 57%
GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent…
Geotools
2.25.7 / 2.26.3+
HIGH 8.2
CVE-2024-34711
GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables …
Geoserver
2.25.0+
CRITICAL 9.1
CVE-2025-31039
Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue af…
Mitigation only
HIGH 8.1
CVE-2025-5877
A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functi…
Feng Office
No fix yet
HIGH 8.7
CVE-2025-48882
PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data usi…
Patch available
MEDIUM 6.8
CVE-2025-4338
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could …
Mitigation only
MEDIUM 5.3
CVE-2025-4949
In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement t…
Jgit
5.13.4 / 6.10.1.202505221210+
HIGH 8.7
CVE-2025-27523
XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Dev…
Mitigation only
CRITICAL 9.3
CVE-2025-4641
Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML par…
Patch available
HIGH 8.8
CVE-2025-4639
CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Pee…
Patch available
MEDIUM 6.1
CVE-2025-47778
Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin u…
Patch available
MEDIUM 6.5
CVE-2024-51445
A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XM…
Polarion Alm
2404.4+
HIGH 7.5
CVE-2025-30018
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi…
Supplier Relationship Management
Mitigation only
HIGH 7.5
CVE-2025-2775 KEVEPSS 43%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali…
Sysaid
after 23.3.40
CRITICAL 9.8
CVE-2025-2776 KEVEPSS 64%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function…
Sysaid
after 23.3.40
CRITICAL 9.8
CVE-2025-2777EPSS 72%
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,…
Sysaid
after 23.3.40
HIGH 8.1
CVE-2025-22478
Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An…
Storage Manager
Mitigation only
CRITICAL 9.1
CVE-2025-46726
Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage…
Langroid
0.53.4+
CRITICAL 9.1
CVE-2025-2905
Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (…
Api Manager
after 2.0.0
MEDIUM 6.5
CVE-2025-34490
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H…
Mailessentials
21.8+
MEDIUM 5.0
CVE-2025-2070
An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visite…
Mitigation only
HIGH 7.5
CVE-2025-31497
TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversio…
Mitigation only
HIGH 8.6
CVE-2025-32406
An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse…
Mitigation only
MEDIUM 6.6
CVE-2025-32138
Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue af…
Mitigation only
CRITICAL 9.8
CVE-2025-3241
A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/m…
Youkefu
No fix yet
HIGH 7.7
CVE-2025-31487
The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, an…
Patch available
MEDIUM 6.5
CVE-2025-1781
There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side …
Css Validator
20250226+
MEDIUM 5.3
CVE-2025-29932
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
Goland
2025.1+