Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 6.8 CVE-2025-25036 Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlat… Mitigation only Fix from $1,6002025-03-21 MEDIUM 6.3 CVE-2025-2365 A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the… Mitigation only Fix from $1,6002025-03-17 MEDIUM 5.5 CVE-2025-27136 LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's bucket creation endpoint is vuln… Patch available Fix from $1,6002025-03-10 HIGH 7.1 CVE-2025-0162 IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti… Aspera Shares 1.10.0+ Fix from $1,9502025-03-07 CRITICAL 9.8 CVE-2023-38693 Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoi… Mitigation only Fix from $2,3002025-03-05 HIGH 7.1 CVE-2024-49781 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote… Openpages With Watson 8.3.0.3 / 9.0.0.5+ Fix from $1,9502025-02-20 HIGH 8.2 CVE-2023-47160 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when p… Cognos Controller 11.0.1.4+ Fix from $1,9502025-02-19 MEDIUM 6.3 CVE-2025-1225 A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-… Yimioa 2024-07-04+ Fix from $1,6002025-02-12 HIGH 7.1 CVE-2024-54171 IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit thi… Entirex Mitigation only Fix from $1,9502025-02-06 HIGH 7.1 CVE-2024-49352 IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injec… Cognos Analytics 11.2.4 / 12.0.4+ Fix from $1,9502025-02-05 HIGH 8.6 CVE-2024-52807 The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by vario… Patch available Fix from $1,9502025-01-24 HIGH 7.5 CVE-2025-23195 An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 7.8 CVE-2024-12476 CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation inte… Mitigation only Fix from $1,9502025-01-17 MEDIUM 5.5 CVE-2024-12298 We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse thi… Mitigation only Fix from $1,6002025-01-14 HIGH 7.5 CVE-2024-46602 An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an att… G5dfr Firmware 1.2.2.19+ Fix from $1,9502025-01-07 HIGH 7.5 CVE-2024-46603 An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of S… G5dfr Firmware 1.2.2.19+ Fix from $1,9502025-01-07 HIGH 7.2 CVE-2024-56322 GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration rep… Gocd 24.5.0+ Fix from $1,9502025-01-03 HIGH 7.1 CVE-2024-56324 GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration f… Gocd 24.5.0+ Fix from $1,9502025-01-03 CRITICAL 9.1 CVE-2024-40896 In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX… Libxml2 2.11.9 / 2.12.9+ Fix from $2,3002024-12-23 HIGH 7.1 CVE-2024-56356 In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack Teamcity 2024.12+ Fix from $1,9502024-12-20 CRITICAL 9.8 CVE-2024-55081 An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code v… Mitigation only Fix from $2,3002024-12-19 MEDIUM 5.3 CVE-2021-22501 Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation.  The vuln… Mitigation only Fix from $1,6002024-12-19 HIGH 8.6 CVE-2024-55887 Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable t… Mitigation only Fix from $1,9502024-12-13 CRITICAL 9.8 CVE-2024-55875 http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln… Patch available Fix from $2,3002024-12-12 MEDIUM 6.5 CVE-2024-49064 Microsoft SharePoint Information Disclosure Vulnerability Sharepoint Server No fix yet Fix from $1,6002024-12-12 MEDIUM 6.3 CVE-2024-49535 Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of X… Acrobat 20.005.30748 / 24.001.30225+ Fix from $1,6002024-12-10 MEDIUM 5.1 CVE-2024-54005 A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V1… Mitigation only Fix from $1,6002024-12-10 MEDIUM 5.5 CVE-2024-49704 A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V1… Mitigation only Fix from $1,6002024-12-10 MEDIUM 5.3 CVE-2024-47582 Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion att… Mitigation only Fix from $1,6002024-12-10 CRITICAL 9.8 CVE-2024-46455 unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser. Mitigation only Fix from $2,3002024-12-09