Vulnerability index

Browse CVEs

70 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2026-65432 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-49875 Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 MEDIUM 5.3 CVE-2026-44618 Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to … Cxf 3.6.11 / 4.1.6+ Fix from $1,6002026-05-22 CRITICAL 9.1 CVE-2026-40682 XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0… Opennlp 2.5.9+ Fix from $2,3002026-05-04 HIGH 8.1 CVE-2025-68493EPSS 37% Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from… Struts 6.1.1+ Fix from $1,9502026-01-11 MEDIUM 6.5 CVE-2025-68280 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when pars… Spatial Information System after 1.5 Fix from $1,6002026-01-05 CRITICAL 9.8 CVE-2025-66516EPSS 79% Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an a… Tika 3.2.2+ Fix from $2,3002025-12-04 HIGH 8.4 CVE-2025-54988EPSS 9% Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out… Tika 3.2.2+ Fix from $1,9502025-08-20 HIGH 8.8 CVE-2025-53689 Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to … Jackrabbit 2.20.17+ Fix from $1,9502025-07-14 HIGH 7.5 CVE-2025-23195 An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab… Ambari 2.7.9+ Fix from $1,9502025-01-21 HIGH 7.5 CVE-2024-28168 Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: … Formatting Objects Processor Mitigation only Fix from $1,9502024-10-09 HIGH 8.8 CVE-2023-48362 XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi… Drill 1.21.2+ Fix from $1,9502024-07-24 MEDIUM 6.5 CVE-2023-50380 XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De… Ambari 2.7.8+ Fix from $1,6002024-02-27 CRITICAL 9.8 CVE-2023-49733 Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User… Cocoon 2.3.0+ Fix from $2,3002023-11-30 HIGH 8.2 CVE-2022-46751 Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I… Ivy 2.5.2+ Fix from $1,9502023-08-21 HIGH 7.5 CVE-2023-22832 The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i… Nifi after 1.19.1 Fix from $1,9502023-02-10 HIGH 7.5 CVE-2022-40705 An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files … Soap Mitigation only Fix from $1,9502022-09-22 CRITICAL 9.8 CVE-2022-39135 Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe… Calcite 1.32.0+ Fix from $2,3002022-09-11 CRITICAL 9.8 CVE-2022-35741EPSS 8% Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit… Cloudstack 4.16.1.1+ Fix from $2,3002022-07-18 CRITICAL 9.8 CVE-2022-28890 A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers… Jena Mitigation only Fix from $2,3002022-05-05 HIGH 7.5 CVE-2022-29265 Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content … Nifi after 1.16.0 Fix from $1,9502022-04-30 CRITICAL 9.1 CVE-2022-25312 An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions … Any23 2.7+ Fix from $2,3002022-03-05 MEDIUM 6.5 CVE-2021-40439 Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia… Openoffice after 4.1.10 Fix from $1,6002021-10-07 HIGH 7.5 CVE-2021-39239 A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex… Jena after 4.1.0 Fix from $1,9502021-09-16 CRITICAL 9.1 CVE-2021-38555 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X… Any23 2.5+ Fix from $2,3002021-09-11 HIGH 7.5 CVE-2021-33813EPSS 19% An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. Solr after 2.0.6 Fix from $1,9502021-06-16 CRITICAL 9.1 CVE-2021-23901 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa… Nutch 1.18+ Fix from $2,3002021-01-25 MEDIUM 5.5 CVE-2020-13940 In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini… Nifi after 1.11.4 Fix from $1,6002020-10-01 HIGH 7.5 CVE-2020-11991EPSS 72% When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc… Cocoon after 2.1.12 Fix from $1,9502020-09-11