CVE z tagiem xxe — 81 wyników. ← Wszystkie tagi

CVE-2016-9563 🔴 Łataj teraz KEV

BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~him~uwlconn~provider~web/bpemuwlconn URI, aka SAP Security Note 2296909.

6.5 CVSS
58.8% EPSS
sapxxe 2016-11-23
CVE-2014-0644 🟡 Monitoruj

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to …

7.8 CVSS
74.0% EPSS
emcxxe 2014-04-17
CVE-2014-0002 🟡 Monitoruj
apps

The XSLT component in Apache Camel before 2.11.4 and 2.12.x before 2.12.3 allows remote attackers to read arbitrary files and possibly have other unspecified impact via an XML document containing an external entity decla…

7.5 CVSS
28.7% EPSS
apacheexploitxxe 2014-03-21
CVE-2024-55875 🟠 Łataj w tym tygodniu

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, …

9.8 CVSS
8.1% EPSS
dosssrfxxe 2024-12-12
CVE-2020-10683 🟠 Łataj w tym tygodniu
appsos

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe,…

9.8 CVSS
7.3% EPSS
oraclexxe 2020-05-01
CVE-2020-25649 🟡 Monitoruj
appsos

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is …

7.5 CVSS
17.6% EPSS
oraclexxe 2020-12-03
CVE-2021-45024 🟠 Łataj w tym tygodniu

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

9.8 CVSS
1.0% EPSS
rocketsoftwarexxe 2022-06-17
CVE-2026-56817 🟠 Łataj w tym tygodniu

Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final, any caller that can deliver bytes to a Netty c…

9.8 CVSS
0.4% EPSS
nettyxxe 2026-07-21
CVE-2026-51080 🟠 Łataj w tym tygodniu

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

9.8 CVSS
0.3% EPSS
proxmoxxxe 2026-07-17
CVE-2024-7098 🟠 Łataj w tym tygodniu

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure: before 4.6.2.

9.8 CVSS
0.2% EPSS
sfsxxe 2024-09-16
CVE-2026-47898 🟠 Łataj w tym tygodniu
apps

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Apache Lucene.Net.Analysis.Common: from 4.8.0-beta00005 before 4.8.0-beta…

9.8 CVSS
0.1% EPSS
apachexxe 2026-07-03
CVE-2026-40042 🟠 Łataj w tym tygodniu

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious…

9.8 CVSS
0.1% EPSS
xxe 2026-04-13
CVE-2022-0239 🔴 Łataj teraz

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

9.8 CVSS
0.0% EPSS
stanfordexploitxxe 2022-01-17
CVE-2026-38429 🟠 Łataj w tym tygodniu

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

9.8 CVSS
0.0% EPSS
xxe 2026-05-05
CVE-2026-48359 🟠 Łataj w tym tygodniu

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged at…

9.6 CVSS
0.5% EPSS
adobercexxe 2026-07-14
CVE-2020-25912 🔴 Łataj teraz

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

9.1 CVSS
1.3% EPSS
CVE-2016-2908 🟠 Łataj w tym tygodniu

IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when processing XML data by the XML parser. A remote attacker could exploit this v…

9.1 CVSS
0.9% EPSS
ibmdosxxe 2017-02-01
CVE-2026-24400 🟠 Łataj w tym tygodniu

AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.x…

9.1 CVSS
0.5% EPSS
assertjdosssrfxxe 2026-01-26
CVE-2026-40682 🟠 Łataj w tym tygodniu
apps

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a s…

9.1 CVSS
0.5% EPSS
apachessrfxxe 2026-05-04
CVE-2026-55471 🔴 Łataj teraz

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.XsltUtilities saxonTransform(...) overloads instantiated a bare net.sf.saxo…

9.1 CVSS
0.3% EPSS
CVE-2026-4374 🟠 Łataj w tym tygodniu

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized D…

9.1 CVSS
0.2% EPSS
rtixxe 2026-04-01
CVE-2025-14543 🟠 Łataj w tym tygodniu

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, f…

9.1 CVSS
0.2% EPSS
rtixxe 2026-04-30
CVE-2017-15685 🟡 Monitoruj

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.

8.6 CVSS
1.7% EPSS
craftercmsxxe 2020-11-27
CVE-2026-36765 🟡 Monitoruj

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

8.8 CVSS
0.1% EPSS
xxe 2026-04-30
CVE-2026-20224 🟡 Monitoruj
network

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does no…

8.6 CVSS
0.7% EPSS
ciscoxxe 2026-05-14
CVE-2026-3511 🟡 Monitoruj

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain u…

8.6 CVSS
0.0% EPSS
ssrfxxe 2026-03-19
CVE-2018-1259 🟡 Monitoruj
cloud

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML exte…

7.5 CVSS
5.0% EPSS
broadcomxxe 2018-05-11
CVE-2026-40998 🟡 Monitoruj

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's harde…

8.2 CVSS
0.4% EPSS
xxe 2026-06-11
CVE-2026-10025 🟡 Monitoruj

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulnerability resides in the parseXmlPayload() function within the event pro…

8.2 CVSS
0.3% EPSS
ibmxxe 2026-08-05
CVE-2016-6059 🟡 Monitoruj

IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly…

8.1 CVSS
0.4% EPSS
ibmdosxxe 2017-02-01
CVE-2016-8980 🟡 Monitoruj

IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive…

8.1 CVSS
0.4% EPSS
ibmdosxxe 2017-02-01
CVE-2023-24187 🟡 Monitoruj

An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/designer/saveReportFile.

7.8 CVSS
0.9% EPSS
CVE-2023-42344 🟡 Monitoruj

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

7.3 CVSS
2.9% EPSS
xxe 2026-05-08
CVE-2022-45588 🟡 Monitoruj

All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should download the R2022-09 release or later and use it in place of the previou…

7.8 CVSS
0.2% EPSS
talendxxe 2023-02-03
CVE-2026-13449 🟡 Monitoruj

IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sens…

7.6 CVSS
0.4% EPSS
ibmxxe 2026-06-30
CVE-2026-29924 🟡 Monitoruj

Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.

7.6 CVSS
0.1% EPSS
getgravxxe 2026-03-30
CVE-2026-65432 🟡 Monitoruj
apps

Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <xsd:import> referenced from that top-level WSDL is handed off to WSDL4J…

7.5 CVSS
0.4% EPSS
apachexxe 2026-08-06
CVE-2026-50782 🟡 Monitoruj

Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp endpoint. An unauthenticated remote attacker can send a crafted XML pa…

7.5 CVSS
0.4% EPSS
xxe 2026-07-29
CVE-2026-44020 🟡 Monitoruj

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parser used the standard xml.sax.parseString()…

7.5 CVSS
0.3% EPSS
doclingdosssrfxxe 2026-06-24
CVE-2026-8396 🟡 Monitoruj

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This issue affects NetGIS: from 5.0.66 before 7.2.2.

7.5 CVSS
0.3% EPSS
xxe 2026-07-17
CVE-2023-42346 🟡 Monitoruj

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

7.5 CVSS
0.1% EPSS
xxe 2026-05-08
CVE-2026-31248 🟡 Monitoruj

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution.…

7.5 CVSS
0.1% EPSS
dosxxe 2026-05-11
CVE-2025-61813 🟡 Monitoruj

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exp…

7.4 CVSS
0.5% EPSS
adobexxe 2025-12-10
CVE-2026-31247 🟡 Monitoruj

Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML fil…

7.5 CVSS
0.0% EPSS
dosxxe 2026-05-11
CVE-2026-47960 🟡 Monitoruj

ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this…

7.4 CVSS
0.5% EPSS
adobexxe 2026-06-09
CVE-2014-0054 ⚪ Do wiadomości

The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a d…

6.8 CVSS
2.5% EPSS
springsourcedosxxe 2014-04-17
CVE-2026-57303 🟡 Monitoruj
dev

Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers able to control the responses of the configured Assembla server to extract secret…

7.1 CVSS
0.2% EPSS
jenkinsssrfxxe 2026-06-24
CVE-2026-70448 🟡 Monitoruj

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.

7.1 CVSS
0.2% EPSS
xxe 2026-08-05
CVE-2022-22977 🟡 Monitoruj
cloud

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative local user privileges in the Windows guest OS, where VMware Tools is inst…

7.1 CVSS
0.0% EPSS
vmwarexxe 2022-05-24
CVE-2026-3603 🟡 Monitoruj

IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection …

7.1 CVSS
0.0% EPSS
ibmxxe 2026-05-26
CVE-2026-22186 🟡 Monitoruj

Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilde…

7.1 CVSS
0.0% EPSS
CVE-2025-61821 ⚪ Do wiadomości

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exp…

6.8 CVSS
0.4% EPSS
adobexxe 2025-12-10
CVE-2026-48981 ⚪ Do wiadomości

pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing libxml2 to process ext…

6.7 CVSS
0.1% EPSS
xxe 2026-06-18
CVE-2016-3027 ⚪ Do wiadomości

IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose high…

6.5 CVSS
0.6% EPSS
ibmdosxxe 2017-02-01
CVE-2015-7743 ⚪ Do wiadomości

XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creating a new HTTP XML/REST Value sensor that accesses a crafted XML file.

6.5 CVSS
0.3% EPSS
paesslerexploitxxe 2017-01-23
CVE-2026-70423 ⚪ Do wiadomości

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerabil…

6.5 CVSS
0.3% EPSS
dellxxe 2026-08-19
CVE-2026-8045 ⚪ Do wiadomości

CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits craf…

6.5 CVSS
0.2% EPSS
CVE-2026-54082 ⚪ Do wiadomości

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity vulnerability in PDFAValidator.validate(...) and GF…

6.5 CVSS
0.2% EPSS
xxe 2026-07-29
CVE-2024-50442 ⚪ Do wiadomości

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through <= 1.3.980.

6.5 CVSS
0.2% EPSS
CVE-2024-5625 ⚪ Do wiadomości

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization External Entities Blowup. This issue affects Apinizer Management Console…

6.5 CVSS
0.2% EPSS
xxe 2024-07-18
CVE-2026-67268 ⚪ Do wiadomości

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability…

6.5 CVSS
0.1% EPSS
CVE-2026-39053 ⚪ Do wiadomości

Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils.fromXML(...) or View…

6.5 CVSS
0.1% EPSS
ssrfxxe 2026-05-15
CVE-2026-44445 ⚪ Do wiadomości

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enables an authenticated …

6.5 CVSS
0.0% EPSS
frappexxe 2026-05-13
CVE-2026-2074 ⚪ Do wiadomości

A vulnerability was identified in O2OA up to 9.0.0. This impacts an unknown function of the file /x_program_center/jaxrs/mpweixin/check of the component HTTP POST Request Handler. The manipulation leads to xml external e…

6.3 CVSS
0.3% EPSS
zonelandexploitxxe 2026-02-07
CVE-2026-12788 ⚪ Do wiadomości

A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of the component XML Parse…

6.3 CVSS
0.2% EPSS
xxe 2026-06-21
CVE-2023-49234 ⚪ Do wiadomości

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files and exfiltrate data to an external server.

6.3 CVSS
0.1% EPSS
xxe 2024-03-29
CVE-2026-40991 ⚪ Do wiadomości
cloud

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an …

5.9 CVSS
0.2% EPSS
broadcomxxe 2026-06-10
CVE-2024-28039 ⚪ Do wiadomości

Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker to obtain sensitive information, alter data, or cause a denial-of-servi…

5.8 CVSS
0.1% EPSS
dosxxe 2024-03-18
CVE-2026-14304 ⚪ Do wiadomości

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External…

5.5 CVSS
0.1% EPSS
eclipsexxe 2026-08-05
CVE-2026-44618 ⚪ Do wiadomości
apps

Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks. Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this issue.

5.3 CVSS
0.3% EPSS
apachexxe 2026-05-22
CVE-2026-28809 ⚪ Do wiadomości

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via c…

5.3 CVSS
0.3% EPSS
arekinathssrfxxe 2026-03-23
CVE-2026-54470 ⚪ Do wiadomości

Dell Unisphere for PowerMax, version(s) 10.3.0.5 and prior contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vu…

5.3 CVSS
0.2% EPSS
dellxxe 2026-07-10
CVE-2026-33737 ⚪ Do wiadomości

Chamilo LMS is a learning management system. Prior to 1.11.38 and 2.0.0-RC.3, multiple files use simplexml_load_string() without XXE protection. With LIBXML_NOENT flag, arbitrary server files can be read. This vulnerabil…

5.3 CVSS
0.0% EPSS
chamiloxxe 2026-04-10
CVE-2025-68463 ⚪ Do wiadomości

Bio.Entrez in Biopython through 186 allows doctype XXE.

4.9 CVSS
0.1% EPSS
xxe 2025-12-18
CVE-2026-33371 ⚪ Do wiadomości

An issue was discovered in Zimbra Collaboration (ZCS) 10.0 and 10.1. An XML External Entity (XXE) vulnerability exists in the Zimbra Exchange Web Services (EWS) SOAP interface due to improper handling of XML input. An au…

4.3 CVSS
0.0% EPSS
xxe 2026-03-20
CVE-2026-49383 ⚪ Do wiadomości

In JetBrains IntelliJ IDEA before 2026.1 xXE in the UI Designer form parser was possible

3.3 CVSS
0.1% EPSS
jetbrainsxxe 2026-05-29
CVE-2026-57234 ⚪ Do wiadomości

Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not corre…

2.6 CVSS
0.2% EPSS
nokogirissrfxxe 2026-06-25
CVE-2026-54078 ⚪ Do wiadomości

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation-model/src/main/ja…

0.0 CVSS
0.3% EPSS
xxe 2026-07-29
CVE-2026-54079 ⚪ Do wiadomości

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-validation contains an XML External Entity (XXE) vulnerability in validation…

0.0 CVSS
0.3% EPSS
xxe 2026-07-29
CVE-2026-57917 ⚪ Do wiadomości 🇵🇱 CERT.pl

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity…

0.0 CVSS
0.1% EPSS
ssrfxxe 2026-07-27
CVE-2026-6501 ⚪ Do wiadomości

Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serialization External Entities Blowup. This issue affects jOpenDocument: 1.5.

0.0 CVSS
0.1% EPSS
xxe 2026-05-04