Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-76572 |
|
Vulnerability in CVE-2026-76572 (CVE-2026-76572)
vulnerability in CVE-2026-76572 (CVE-2026-76572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-73235 |
|
XXE (XML External Entity) in cpp (CVE-2026-73235)
vulnerability in cpp (CVE-2026-73235). Confidential information can be exposed externally.
|
| CVE-2026-54078 |
|
XXE (XML External Entity) in org.verapdf:validation-model (CVE-2026-54078)
vulnerability in org.verapdf:validation-model (CVE-2026-54078). Risk of unauthorized operations or information disclosure. Exploitable via ``DocumentBuilderFactory``. Mitigation: upgrade to `1.31.71` or later.
|
| CVE-2026-54079 |
|
XXE (XML External Entity) in org.verapdf:validation-model (CVE-2026-54079)
vulnerability in org.verapdf:validation-model (CVE-2026-54079). Risk of unauthorized operations or information disclosure. Exploitable via ``DocumentBuilderFactory``. Mitigation: upgrade to `1.31.71` or later.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-57234 |
|
Vulnerability in ssrf (CVE-2026-57234)
vulnerability in ssrf (CVE-2026-57234). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.19.4` or later.
|
| CVE-2026-55471 |
|
XXE (XML External Entity) in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471). Confidential information can be exposed externally. Exploitable via `GET /evil-fhir-xslt-ssrf.dtd`. Mitigation: upgrade to `6.9.10` or later.
|
| CVE-2026-45071 |
|
XXE (XML External Entity) in symfony/dom-crawler (CVE-2026-45071)
vulnerability in symfony/dom-crawler (CVE-2026-45071). Confidential information can be exposed externally. Exploitable via ``Crawler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-42212 |
|
Vulnerability in csharp (CVE-2026-42212)
vulnerability in csharp (CVE-2026-42212). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-26171 |
|
Vulnerability in dotnet (CVE-2026-26171)
vulnerability in dotnet (CVE-2026-26171). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.26, 9.0.15, 10.0.6` or later.
|
| CVE-2022-21282 |
|
XXE (XML External Entity) in java (CVE-2022-21282)
vulnerability in java (CVE-2022-21282). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.0, 1.8.0, 7.0.331, 8.0.321, 11.0.14, 17.0.2` or later.
|
| CVE-2026-40682 |
|
XXE (XML External Entity) in org.apache.opennlp:opennlp-tools (CVE-2026-40682)
vulnerability in org.apache.opennlp:opennlp-tools (CVE-2026-40682). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-M3` or later.
|
| CVE-2026-22016 |
|
Information Disclosure in java (CVE-2026-22016)
vulnerability in java (CVE-2026-22016). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.0, 8.0.491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1` or later.
|
| CVE-2024-45490 |
|
Vulnerability in c (CVE-2024-45490)
vulnerability in c (CVE-2024-45490). Risk of unauthorized operations or information disclosure.
|
| CVE-2020-25912 |
|
XXE (XML External Entity) in dos (CVE-2020-25912)
vulnerability in dos (CVE-2020-25912). Confidential information can be exposed externally.
|
| CVE-2014-3630 |
|
XXE (XML External Entity) in dos (CVE-2014-3630)
vulnerability in dos (CVE-2014-3630). Successful exploitation can lead to full system takeover.
|
| CVE-2017-12629 |
|
XXE (XML External Entity) in c (CVE-2017-12629)
vulnerability in c (CVE-2017-12629). Successful exploitation can lead to full system takeover.
|
| CVE-2017-10617 |
|
XXE (XML External Entity) in c (CVE-2017-10617)
vulnerability in c (CVE-2017-10617). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-12069 |
|
XXE (XML External Entity) in csharp (CVE-2017-12069)
vulnerability in csharp (CVE-2017-12069). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9233 |
|
XXE (XML External Entity) in libexpat-project (CVE-2017-9233)
vulnerability in libexpat-project (CVE-2017-9233). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-11457 |
|
XXE (XML External Entity) in ssrf (CVE-2017-11457)
vulnerability in ssrf (CVE-2017-11457). Confidential information can be exposed externally.
|
| CVE-2017-10670 |
|
XXE (XML External Entity) in csharp (CVE-2017-10670)
vulnerability in csharp (CVE-2017-10670). Successful exploitation can lead to full system takeover.
|
| CVE-2017-8913 |
|
XXE (XML External Entity) in sap (CVE-2017-8913)
vulnerability in sap (CVE-2017-8913). Successful exploitation can lead to full system takeover.
|
| CVE-2017-1289 |
|
XXE (XML External Entity) in ibm (CVE-2017-1289)
vulnerability in ibm (CVE-2017-1289). Confidential information can be exposed externally.
|
| CVE-2017-8110 |
|
XXE (XML External Entity) in modified-shop (CVE-2017-8110)
vulnerability in modified-shop (CVE-2017-8110). Successful exploitation can lead to full system takeover.
|
| CVE-2017-3548 |
|
XXE (XML External Entity) in c (CVE-2017-3548)
vulnerability in c (CVE-2017-3548). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6055 |
|
XXE (XML External Entity) in eparaksts (CVE-2017-6055)
vulnerability in eparaksts (CVE-2017-6055). Successful exploitation can lead to full system takeover.
|
| CVE-2017-5992 |
|
XXE (XML External Entity) in openpyxl (CVE-2017-5992)
vulnerability in openpyxl (CVE-2017-5992). Confidential information can be exposed externally.
|