Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-55848 |
|
XXE (XML External Entity) in org.mapfish.print:print-lib (CVE-2026-55848)
vulnerability in org.mapfish.print:print-lib (CVE-2026-55848). Confidential information can be exposed externally. Mitigation: upgrade to `4.0.5` or later.
|
| CVE-2026-76572 |
|
Vulnerability in CVE-2026-76572 (CVE-2026-76572)
vulnerability in CVE-2026-76572 (CVE-2026-76572). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-20320 |
|
XXE (XML External Entity) in cisco (CVE-2026-20320)
vulnerability in cisco (CVE-2026-20320). Confidential information can be exposed externally.
|
| CVE-2026-67268 |
|
XXE (XML External Entity) in dell (CVE-2026-67268)
vulnerability in dell (CVE-2026-67268). Confidential information can be exposed externally.
|
| CVE-2026-70423 |
|
XXE (XML External Entity) in dell (CVE-2026-70423)
vulnerability in dell (CVE-2026-70423). Confidential information can be exposed externally.
|
| CVE-2026-18715 |
|
XXE (XML External Entity) in ibm (CVE-2026-18715)
vulnerability in ibm (CVE-2026-18715). Confidential information can be exposed externally.
|
| CVE-2026-65432 |
|
XXE (XML External Entity) in apache (CVE-2026-65432)
vulnerability in apache (CVE-2026-65432). Confidential information can be exposed externally.
|
| CVE-2026-10025 |
|
XXE (XML External Entity) in ibm (CVE-2026-10025)
vulnerability in ibm (CVE-2026-10025). Confidential information can be exposed externally.
|
| CVE-2026-54078 |
|
XXE (XML External Entity) in org.verapdf:validation-model (CVE-2026-54078)
vulnerability in org.verapdf:validation-model (CVE-2026-54078). Risk of unauthorized operations or information disclosure. Exploitable via ``DocumentBuilderFactory``. Mitigation: upgrade to `1.31.71` or later.
|
| CVE-2026-54079 |
|
XXE (XML External Entity) in org.verapdf:validation-model (CVE-2026-54079)
vulnerability in org.verapdf:validation-model (CVE-2026-54079). Risk of unauthorized operations or information disclosure. Exploitable via ``DocumentBuilderFactory``. Mitigation: upgrade to `1.31.71` or later.
|
| CVE-2026-48359 |
|
XXE (XML External Entity) in adobe (CVE-2026-48359)
vulnerability in adobe (CVE-2026-48359). Confidential information can be exposed externally.
|
| CVE-2026-54470 |
|
XXE (XML External Entity) in dell (CVE-2026-54470)
vulnerability in dell (CVE-2026-54470). Confidential information can be exposed externally.
|
| CVE-2026-57259 |
|
XXE (XML External Entity) in foxit (CVE-2026-57259)
vulnerability in foxit (CVE-2026-57259). Confidential information can be exposed externally.
|
| CVE-2026-47898 |
|
XXE (XML External Entity) in csharp (CVE-2026-47898)
vulnerability in csharp (CVE-2026-47898). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13449 |
|
XXE (XML External Entity) in ibm (CVE-2026-13449)
vulnerability in ibm (CVE-2026-13449). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55471 |
|
XXE (XML External Entity) in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471)
vulnerability in ca.uhn.hapi.fhir:org.hl7.fhir.utilities (CVE-2026-55471). Confidential information can be exposed externally. Exploitable via `GET /evil-fhir-xslt-ssrf.dtd`. Mitigation: upgrade to `6.9.10` or later.
|
| CVE-2025-58175 |
|
Vulnerability in org.geoserver.web:gs-web-app (CVE-2025-58175)
vulnerability in org.geoserver.web:gs-web-app (CVE-2025-58175). Confidential information can be exposed externally. Exploitable via ``ENTITY_RESOLUTION_ALLOWLIST``. Mitigation: upgrade to `2.27.3` or later.
|
| CVE-2026-49875 |
|
XXE (XML External Entity) in apache (CVE-2026-49875)
vulnerability in apache (CVE-2026-49875). Successful exploitation can lead to full system takeover.
|
| CVE-2026-40991 |
|
XXE (XML External Entity) in org.springframework.restdocs:spring-restdocs-webtestclient (CVE-2026-40991)
vulnerability in org.springframework.restdocs:spring-restdocs-webtestclient (CVE-2026-40991). Confidential information can be exposed externally.
|
| CVE-2026-47960 |
|
XXE (XML External Entity) in adobe (CVE-2026-47960)
vulnerability in adobe (CVE-2026-47960). Confidential information can be exposed externally.
|
| CVE-2026-8045 |
|
XXE (XML External Entity) in schneider-electric (CVE-2026-8045)
vulnerability in schneider-electric (CVE-2026-8045). Confidential information can be exposed externally.
|
| CVE-2026-49383 |
|
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible
|
| CVE-2026-45071 |
|
XXE (XML External Entity) in symfony/dom-crawler (CVE-2026-45071)
vulnerability in symfony/dom-crawler (CVE-2026-45071). Confidential information can be exposed externally. Exploitable via ``Crawler``. Mitigation: upgrade to `8.0.12` or later.
|
| CVE-2026-3603 |
|
XXE (XML External Entity) in ibm (CVE-2026-3603)
vulnerability in ibm (CVE-2026-3603). Confidential information can be exposed externally.
|
| CVE-2026-44618 |
|
XXE (XML External Entity) in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618)
vulnerability in org.apache.cxf:cxf-rt-ws-transfer (CVE-2026-44618). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.6.11` or later.
|
| CVE-2026-26171 |
|
Vulnerability in dotnet (CVE-2026-26171)
vulnerability in dotnet (CVE-2026-26171). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `8.0.26, 9.0.15, 10.0.6` or later.
|
| CVE-2022-21282 |
|
XXE (XML External Entity) in java (CVE-2022-21282)
vulnerability in java (CVE-2022-21282). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.7.0, 1.8.0, 7.0.331, 8.0.321, 11.0.14, 17.0.2` or later.
|
| CVE-2026-40682 |
|
XXE (XML External Entity) in org.apache.opennlp:opennlp-tools (CVE-2026-40682)
vulnerability in org.apache.opennlp:opennlp-tools (CVE-2026-40682). Confidential information can be exposed externally. Mitigation: upgrade to `3.0.0-M3` or later.
|
| CVE-2026-22016 |
|
Information Disclosure in java (CVE-2026-22016)
vulnerability in java (CVE-2026-22016). Confidential information can be exposed externally. Mitigation: upgrade to `1.8.0, 8.0.491, 11.0.31, 17.0.19, 21.0.11, 25.0.3, 26.0.1` or later.
|
| CVE-2026-34401 |
|
XXE (XML External Entity) in microsoft (CVE-2026-34401)
vulnerability in microsoft (CVE-2026-34401). Confidential information can be exposed externally.
|
| CVE-2025-68493 |
|
XXE (XML External Entity) in apache (CVE-2025-68493)
vulnerability in apache (CVE-2025-68493). Confidential information can be exposed externally.
|
| CVE-2025-58360 KEV |
|
[KEV] XXE (XML External Entity) in Osgeo geoserver (CVE-2025-58360)
vulnerability in Osgeo geoserver (CVE-2025-58360). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-61821 |
|
XXE (XML External Entity) in adobe (CVE-2025-61821)
vulnerability in adobe (CVE-2025-61821). Confidential information can be exposed externally.
|
| CVE-2025-61813 |
|
XXE (XML External Entity) in adobe (CVE-2025-61813)
vulnerability in adobe (CVE-2025-61813). Confidential information can be exposed externally.
|
| CVE-2025-2775 KEV |
|
[KEV] XXE (XML External Entity) in sysaid (CVE-2025-2775)
vulnerability in sysaid (CVE-2025-2775). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2025-2776 KEV |
|
[KEV] XXE (XML External Entity) in sysaid (CVE-2025-2776)
vulnerability in sysaid (CVE-2025-2776). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-45727 KEV |
|
[KEV] XXE (XML External Entity) in North grid north-grid (CVE-2023-45727)
vulnerability in North grid north-grid (CVE-2023-45727). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2024-34102 KEV |
|
[KEV] XXE (XML External Entity) in Adobe commerce-and-magento-open-source (CVE-2024-34102)
vulnerability in Adobe commerce-and-magento-open-source (CVE-2024-34102). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2023-35389 |
|
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability
|
| CVE-2020-25912 |
|
XXE (XML External Entity) in dos (CVE-2020-25912)
vulnerability in dos (CVE-2020-25912). Confidential information can be exposed externally.
|
| CVE-2022-22977 |
|
XXE (XML External Entity) in vmware (CVE-2022-22977)
vulnerability in vmware (CVE-2022-22977). Confidential information can be exposed externally.
|
| CVE-2019-9670 KEV |
|
[KEV] XXE (XML External Entity) in Synacor zimbra-collaboration-suite-zcs (CVE-2019-9670)
vulnerability in Synacor zimbra-collaboration-suite-zcs (CVE-2019-9670). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2019-13608 KEV |
|
[KEV] XXE (XML External Entity) in Citrix storefront-server (CVE-2019-13608)
vulnerability in Citrix storefront-server (CVE-2019-13608). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2016-9563 KEV |
|
[KEV] XXE (XML External Entity) in Sap netweaver (CVE-2016-9563)
vulnerability in Sap netweaver (CVE-2016-9563). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
|
| CVE-2020-25649 |
|
XXE (XML External Entity) in fasterxml (CVE-2020-25649)
vulnerability in fasterxml (CVE-2020-25649). Data can be tampered with by attackers.
|
| CVE-2020-10683 |
|
XXE (XML External Entity) in dom4j-project (CVE-2020-10683)
vulnerability in dom4j-project (CVE-2020-10683). Successful exploitation can lead to full system takeover.
|
| CVE-2018-1259 |
|
XXE (XML External Entity) in broadcom (CVE-2018-1259)
vulnerability in broadcom (CVE-2018-1259). Confidential information can be exposed externally.
|
| CVE-2014-3630 |
|
XXE (XML External Entity) in dos (CVE-2014-3630)
vulnerability in dos (CVE-2014-3630). Successful exploitation can lead to full system takeover.
|
| CVE-2017-11286 |
|
XXE (XML External Entity) in adobe (CVE-2017-11286)
vulnerability in adobe (CVE-2017-11286). Confidential information can be exposed externally.
|
| CVE-2017-1477 |
|
XXE (XML External Entity) in ibm (CVE-2017-1477)
vulnerability in ibm (CVE-2017-1477). Confidential information can be exposed externally.
|