Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.8 CVE-2025-36049 IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 is vulnerable to an XML external entity injection (XXE) attack when processing XML d… Webmethods Integration Mitigation only Fix from $1,9502025-06-18 HIGH 7.5 CVE-2025-44044 Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing mal… Mitigation only Fix from $1,9502025-06-10 CRITICAL 9.1 CVE-2025-30220EPSS 57% GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent… Geotools 2.25.7 / 2.26.3+ Fix from $2,3002025-06-10 HIGH 8.2 CVE-2024-34711 GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables … Geoserver 2.25.0+ Fix from $1,9502025-06-10 CRITICAL 9.1 CVE-2025-31039 Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue af… Mitigation only Fix from $2,3002025-06-09 HIGH 8.1 CVE-2025-5877 A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functi… Feng Office No fix yet Fix from $1,9502025-06-09 HIGH 8.7 CVE-2025-48882 PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data usi… Patch available Fix from $1,9502025-05-30 MEDIUM 6.8 CVE-2025-4338 Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could … Mitigation only Fix from $1,6002025-05-22 MEDIUM 5.3 CVE-2025-4949 In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement t… Jgit 5.13.4 / 6.10.1.202505221210+ Fix from $1,6002025-05-21 HIGH 8.7 CVE-2025-27523 XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Dev… Mitigation only Fix from $1,9502025-05-15 CRITICAL 9.3 CVE-2025-4641 Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML par… Patch available Fix from $2,3002025-05-14 HIGH 8.8 CVE-2025-4639 CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Pee… Patch available Fix from $1,9502025-05-14 MEDIUM 6.1 CVE-2025-47778 Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin u… Patch available Fix from $1,6002025-05-14 MEDIUM 6.5 CVE-2024-51445 A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The affected application contains a XM… Polarion Alm 2404.4+ Fix from $1,6002025-05-13 HIGH 7.5 CVE-2025-30018 The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request wi… Supplier Relationship Management Mitigation only Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-2775 KEVEPSS 43% SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionali… Sysaid after 23.3.40 Fix from $1,9502025-05-07 CRITICAL 9.8 CVE-2025-2776 KEVEPSS 64% SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing function… Sysaid after 23.3.40 Fix from $2,3002025-05-07 CRITICAL 9.8 CVE-2025-2777EPSS 72% SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,… Sysaid after 23.3.40 Fix from $2,3002025-05-07 HIGH 8.1 CVE-2025-22478 Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An… Storage Manager Mitigation only Fix from $1,9502025-05-06 CRITICAL 9.1 CVE-2025-46726 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.53.4, a LLM application leveraging `XMLToolMessage… Langroid 0.53.4+ Fix from $2,3002025-05-05 CRITICAL 9.1 CVE-2025-2905 Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (… Api Manager after 2.0.0 Fix from $2,3002025-05-05 MEDIUM 6.5 CVE-2025-34490 GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H… Mailessentials 21.8+ Fix from $1,6002025-04-28 MEDIUM 5.0 CVE-2025-2070 An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visite… Mitigation only Fix from $1,6002025-04-25 HIGH 7.5 CVE-2025-31497 TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversio… Mitigation only Fix from $1,9502025-04-15 HIGH 8.6 CVE-2025-32406 An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse… Mitigation only Fix from $1,9502025-04-08 MEDIUM 6.6 CVE-2025-32138 Improper Restriction of XML External Entity Reference vulnerability in supsystic Easy Google Maps google-maps-easy allows XML Injection.This issue af… Mitigation only Fix from $1,6002025-04-04 CRITICAL 9.8 CVE-2025-3241 A vulnerability, which was classified as problematic, was found in zhangyanbo2007 youkefu up to 4.2.0. This affects an unknown part of the file src/m… Youkefu No fix yet Fix from $2,3002025-04-04 HIGH 7.7 CVE-2025-31487 The XWiki JIRA extension provides various integration points between XWiki and JIRA (macros, UI, CKEditor plugin). If the JIRA macro is installed, an… Patch available Fix from $1,9502025-04-03 MEDIUM 6.5 CVE-2025-1781 There is a XXE in W3CSS Validator versions before cssval-20250226 that allows an attacker to use specially-crafted XML objects to coerce server-side … Css Validator 20250226+ Fix from $1,6002025-03-28 MEDIUM 5.3 CVE-2025-29932 In JetBrains GoLand before 2025.1 an XXE during debugging was possible Goland 2025.1+ Fix from $1,6002025-03-25