Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2026-65432
Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <…
Cxf
3.6.12 / 4.1.8+
CRITICAL 9.8
CVE-2026-47898
Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library).
This issue affects Ap…
Lucene.net
Mitigation only
CRITICAL 9.8
CVE-2026-49875
Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration…
Cxf
4.1.7 / 4.2.2+
MEDIUM 5.3
CVE-2026-44618
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to …
Cxf
3.6.11 / 4.1.6+
CRITICAL 9.1
CVE-2026-40682
XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor
Versions Affected: before 2.5.9, before 3.0…
Opennlp
2.5.9+
HIGH 8.1
CVE-2025-68493EPSS 37%
Missing XML Validation vulnerability in Apache Struts, Apache Struts.
This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from…
Struts
6.1.1+
MEDIUM 6.5
CVE-2025-68280
Improper Restriction of XML External Entity Reference vulnerability in Apache SIS.
It is possible to write XML files in such a way that, when pars…
Spatial Information System
after 1.5
CRITICAL 9.8
CVE-2025-66516EPSS 79%
Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a…
Tika
3.2.2+
HIGH 8.4
CVE-2025-54988EPSS 9%
Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out…
Tika
3.2.2+
HIGH 8.8
CVE-2025-53689
Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to …
Jackrabbit
2.20.17+
HIGH 7.5
CVE-2025-23195
An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
project, allowing an attacker to inject malicious XML entities. This
vulnerab…
Ambari
2.7.9+
HIGH 7.5
CVE-2024-28168
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP.
This issue affects Apache XML Graphics FOP: …
Formatting Objects Processor
Mitigation only
HIGH 8.8
CVE-2023-48362
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…
Drill
1.21.2+
MEDIUM 6.5
CVE-2023-50380
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue.
More De…
Ambari
2.7.8+
CRITICAL 9.8
CVE-2023-49733
Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0.
User…
Cocoon
2.3.0+
HIGH 8.2
CVE-2022-46751
Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I…
Ivy
2.5.2+
HIGH 7.5
CVE-2023-22832
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that i…
Nifi
after 1.19.1
HIGH 7.5
CVE-2022-40705
An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …
Soap
Mitigation only
CRITICAL 9.8
CVE-2022-39135
Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…
Calcite
1.32.0+
CRITICAL 9.8
CVE-2022-35741EPSS 8%
Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…
Cloudstack
4.16.1.1+
CRITICAL 9.8
CVE-2022-28890
A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…
Jena
Mitigation only
HIGH 7.5
CVE-2022-29265
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content …
Nifi
after 1.16.0
CRITICAL 9.1
CVE-2022-25312
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …
Any23
2.7+
MEDIUM 6.5
CVE-2021-40439
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia…
Openoffice
after 4.1.10
HIGH 7.5
CVE-2021-39239
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…
Jena
after 4.1.0
CRITICAL 9.1
CVE-2021-38555
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…
Any23
2.5+
HIGH 7.5
CVE-2021-33813EPSS 19%
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Solr
after 2.0.6
CRITICAL 9.1
CVE-2021-23901
An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…
Nutch
1.18+
MEDIUM 5.5
CVE-2020-13940
In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini…
Nifi
after 1.11.4
HIGH 7.5
CVE-2020-11991EPSS 72%
When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…
Cocoon
after 2.1.12