<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – XML External Entity (XXE) (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/xxe.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/xxe-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – XML External Entity (XXE) (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:38 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-3603 – IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3603</guid>
    <pubDate>Tue, 26 May 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3603</strong></p>
  <p>IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through  Interim Fix 021, 7.1.0  Interim Fix 001 through  Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-20224 – A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-20224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-20224</guid>
    <pubDate>Thu, 14 May 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-20224</strong></p>
  <p>A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have valid user credentials.  This vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing an XML file. An attacker could exploit t…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-20224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31248 – Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31248</guid>
    <pubDate>Mon, 11 May 2026 17:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31248</strong></p>
  <p>Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstring() without disabling entity resolution. An attacker can craft a malicious XML file with nested entity definitions (XML Bomb) and package it into a .tar.gz archive. When processed by Docling, the exponential expansion o…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31247 – Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31247</guid>
    <pubDate>Mon, 11 May 2026 16:17:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31247</strong></p>
  <p>Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse() to parse XML files without disabling entity resolution. An attacker can craft a malicious XML file containing a nested entity expansion payload (XML Bomb). When processed by Docling, the exponential expansion of entities leads to excessive resource consumption, resulting in a…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42346 – Alkacon OpenCms before 16 allows XXE when the &lt;!DOCTYPE&gt; refers to an external h...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42346</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42346</guid>
    <pubDate>Fri, 08 May 2026 05:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42346</strong></p>
  <p>Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42346">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-42344 – Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-42344</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-42344</guid>
    <pubDate>Fri, 08 May 2026 05:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-42344</strong></p>
  <p>Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-42344">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-41936 – Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41936</guid>
    <pubDate>Wed, 06 May 2026 19:16:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-41936</strong></p>
  <p>Vvveb before version 1.0.8.2 contains an XML external entity (XXE) injection vulnerability in the admin Tools/Import feature that allows authenticated site_admin users to read arbitrary files and modify database records. Attackers can exploit the XML parser configuration in system/import/xml.php to inject file:// or php://filter entity references that are resolved and persisted into the applicati…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-38429 – OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-38429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-38429</guid>
    <pubDate>Tue, 05 May 2026 17:17:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-38429</strong></p>
  <p>OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-38429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40682 – XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP D...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40682</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40682</guid>
    <pubDate>Mon, 04 May 2026 17:16:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40682</strong></p>
  <p>XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor   Versions Affected: before 2.5.9, before 3.0.0-M3   Description: The DictionaryEntryPersistor class initializes a static SAXParserFactory at class-load time without enabling FEATURE_SECURE_PROCESSING or disabling DTD processing. When create(InputStream, EntryInserter) is invoked, the only feat…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40682">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-36765 – An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-36765</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-36765</guid>
    <pubDate>Thu, 30 Apr 2026 18:16:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-36765</strong></p>
  <p>An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-36765">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-14543 – Improper Restriction of XML External Entity Reference vulnerability in Connext P...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14543</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14543</guid>
    <pubDate>Thu, 30 Apr 2026 16:16:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-14543</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.*, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*, from 4.3x before 5.2.*.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14543">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-40882 – OpenRemote is an open-source internet-of-things platform. Prior to version 1.22...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40882</guid>
    <pubDate>Wed, 22 Apr 2026 21:17:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-40882</strong></p>
  <p>OpenRemote is an open-source internet-of-things platform. Prior to version 1.22.0, the Velbus asset import path parses attacker-controlled XML without explicit XXE hardening. An authenticated user who can call the import endpoint may trigger XML external entity processing, which can lead to server-side file disclosure and SSRF. The target file must be less than 1023 characters. Version 1.22.0 fix…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-40042 – Pachno 1.0.6 contains an XML external entity injection vulnerability that allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-40042</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-40042</guid>
    <pubDate>Mon, 13 Apr 2026 19:16:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-40042</strong></p>
  <p>Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-403</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-40042">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-4374 – Improper Restriction of XML External Entity Reference vulnerability in RTI Conne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-4374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-4374</guid>
    <pubDate>Wed, 01 Apr 2026 02:16:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-4374</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Routing Service,Observability Collector,Recording Service,Queueing Service,Cloud Discovery Service) allows Serialized Data External Linking, Data Serializat...</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-4374">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29924 – Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29924</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29924</guid>
    <pubDate>Mon, 30 Mar 2026 19:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29924</strong></p>
  <p>Grav CMS v1.7.x and before is vulnerable to XML External Entity (XXE) through the SVG file upload functionality in the admin panel and File Manager plugin.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29924">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-3511 – Improper Restriction of XML External Entity Reference vulnerability in XMLUtils...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-3511</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-3511</guid>
    <pubDate>Thu, 19 Mar 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-3511</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends re…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-3511">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28770 – Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28770</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28770</guid>
    <pubDate>Wed, 04 Mar 2026 07:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28770</strong></p>
  <p>Improper neutralization of special elements in the /IDC_Logging/checkifdone.cgi script in International Datacasting Corporation (IDC) SFX Series SuperFlex Satellite Receiver Web management Interface version 101 allows for XML Injection. The application reflects un-sanitized user input from the `file` parameter directly into a CDATA block, allowing an authenticated attacker to break out of the tag…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28770">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1567 – IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Enti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1567</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1567</guid>
    <pubDate>Tue, 03 Mar 2026 21:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1567</strong></p>
  <p>IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1567">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-2252 – An XML External Entity (XXE) vulnerability allows malicious user to perform Serv...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-2252</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-2252</guid>
    <pubDate>Fri, 27 Feb 2026 09:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-2252</strong></p>
  <p>An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references.  This issue affects Xerox FreeFlow Core versions up to and including 8.0.7.   Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on -  https://www.support.xerox.com/en-us/product/core/…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-2252">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36247 – IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36247</guid>
    <pubDate>Tue, 17 Feb 2026 18:20:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36247</strong></p>
  <p>IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 through 11.5.9 and 12.1.0 through 12.1.3 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-1227 – CWE-611: Improper Restriction of XML External Entity Reference vulnerability exi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-1227</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-1227</guid>
    <pubDate>Wed, 11 Feb 2026 14:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-1227</strong></p>
  <p>CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized disclosure of local files, interaction within the EBO system, or denial of service conditions when a local user uploads a specially crafted TGML graphics file to the EBO server from Workstation.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1227">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-13096 – IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-13096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-13096</guid>
    <pubDate>Mon, 02 Feb 2026 23:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-13096</strong></p>
  <p>IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-13096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-21569 – This High severity XXE (XML External Entity Injection) vulnerability was introdu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-21569</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-21569</guid>
    <pubDate>Wed, 28 Jan 2026 01:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-21569</strong></p>
  <p>This High severity XXE (XML External Entity Injection) vulnerability was introduced in version 7.1.0 of Crowd Data Center and Server.  	 	This XXE (XML External Entity Injection) vulnerability, with a CVSS Score of 7.9, allows an authenticated attacker to access local and remote content which has high impact to confidentiality, low impact to integrity, high impact to availability, and requires no…</p>
  <p><strong>CVSS:</strong> 7.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21569">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-24400 – AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24400</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24400</guid>
    <pubDate>Mon, 26 Jan 2026 23:16:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-24400</strong></p>
  <p>AssertJ provides Fluent testing assertions for Java and the Java Virtual Machine (JVM). Starting in version 1.4.0 and prior to version 3.27.7, an XML External Entity (XXE) vulnerability exists in `org.assertj.core.util.xml.XmlStringPrettyFormatter`: the `toXmlDocument(String)` method initializes `DocumentBuilderFactory` with default settings, without disabling DTDs or external entities. This form…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24400">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-65482 – An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65482</guid>
    <pubDate>Tue, 20 Jan 2026 16:16:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-65482</strong></p>
  <p>An XML External Entity (XXE) vulnerability in opensagres XDocReport v0.9.2 to v2.0.3 allows attackers to execute arbitrary code via uploading a crafted .docx file.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-14478 – The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-14478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-14478</guid>
    <pubDate>Sat, 17 Jan 2026 08:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-14478</strong></p>
  <p>The Demo Importer Plus plugin for WordPress is vulnerable to XML External Entity Injection (XXE) in all versions up to, and including, 2.0.9 via the SVG file upload functionality. This makes it possible for authenticated attackers, with Author-level access and above, to achieve code execution in vulnerable configurations. This only impacts sites on versions of PHP older than 8.0.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-14478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22186 – Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (X...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22186</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22186</guid>
    <pubDate>Wed, 07 Jan 2026 21:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22186</strong></p>
  <p>Bio-Formats versions up to and including 8.3.0 contain an XML External Entity (XXE) vulnerability in the Leica Microsystems metadata parsing component (e.g., XLEF). The parser uses an insecurely configured DocumentBuilderFactory when processing Leica XML-based metadata files, allowing external entity expansion and external DTD loading. A crafted metadata file can trigger outbound network requests…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22186">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36589 – Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restrict...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36589</guid>
    <pubDate>Tue, 06 Jan 2026 17:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36589</strong></p>
  <p>Dell Unisphere for PowerMax, version(s) 9.2.4.x, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized access to data and resources outside of the intended sphere of control.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-25253 – KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-25253</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-25253</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-25253</strong></p>
  <p>KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malicious XML file with external entity references to retrieve sensitive configuration data like database credentials through an out-of-band channel attack.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-25253">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-25142 – NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-25142</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-25142</guid>
    <pubDate>Wed, 24 Dec 2025 20:15:48 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-25142</strong></p>
  <p>NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-25142">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-61813 – ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61813</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61813</guid>
    <pubDate>Wed, 10 Dec 2025 00:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-61813</strong></p>
  <p>ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the server. Exploitation of this issue does requires user interaction and scope is changed.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61813">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-66516 – Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-66516</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-66516</guid>
    <pubDate>Thu, 04 Dec 2025 17:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-66516</strong></p>
  <p>Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF.   This CVE covers the same vulnerability as in CVE-2025-54988. However, this CVE expands the scope of affected packages in two ways.   First, while the entrypo…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-66516">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-65868 – XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-65868</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-65868</guid>
    <pubDate>Wed, 03 Dec 2025 21:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-65868</strong></p>
  <p>XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-65868">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-58360 – GeoServer is an open source server that allows users to share and edit geospatia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58360</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58360</guid>
    <pubDate>Tue, 25 Nov 2025 21:15:56 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-58360</strong></p>
  <p>GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.26.2 and before 2.25.6, an XML External Entity (XXE) vulnerability was identified. The application accepts XML input through a specific endpoint /geoserver/wms operation GetMap. However, this input is not sufficiently sanitized or restricted, allowing an attacker to define exter…</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58360">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63917 – PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does n...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63917</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63917</guid>
    <pubDate>Mon, 17 Nov 2025 17:15:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63917</strong></p>
  <p>PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive data via out-of-band (OOB) HTTP requests, perform SSRF attacks against internal ne…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63917">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64518 – The CycloneDX core module provides a model representation of the SBOM along with...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64518</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64518</guid>
    <pubDate>Mon, 10 Nov 2025 22:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64518</strong></p>
  <p>The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Starting in version 2.1.0 and prior to version 11.0.1, the XML `Validator` used by cyclonedx-core-java was not configured securely, making the library vulnerable to XML External Entity (XXE) injection. The fix for GHSA-683x-4444-jxh8 / CVE-2024-38374 was…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64518">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-63551 – A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML Ex...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-63551</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-63551</guid>
    <pubDate>Thu, 06 Nov 2025 19:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-63551</strong></p>
  <p>A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in MetInfo Content Management System (CMS) thru 8.1. This flaw stems from a defect in the XML parsing logic, which allows an attacker to construct a malicious XML entity that forces the server to initiate an HTTP request to an arbitrary internal or external network address. Succes…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-63551">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-12531 – IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-12531</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-12531</guid>
    <pubDate>Mon, 03 Nov 2025 20:17:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-12531</strong></p>
  <p>IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-12531">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-64134 – Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-64134</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-64134</guid>
    <pubDate>Wed, 29 Oct 2025 14:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-64134</strong></p>
  <p>Jenkins JDepend Plugin 1.3.1 and earlier includes an outdated version of JDepend Maven Plugin that does not configure its XML parser to prevent XML external entity (XXE) attacks.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-64134">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-9066 – A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-9066</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-9066</guid>
    <pubDate>Tue, 14 Oct 2025 13:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-9066</strong></p>
  <p>A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-9066">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6985 – The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulne...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6985</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6985</guid>
    <pubDate>Mon, 06 Oct 2025 18:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6985</strong></p>
  <p>The HTMLSectionSplitter class in langchain-text-splitters version 0.3.8 is vulnerable to XML External Entity (XXE) attacks due to unsafe XSLT parsing. This vulnerability arises because the class allows the use of arbitrary XSLT stylesheets, which are parsed using lxml.etree.parse() and lxml.etree.XSLT() without any hardening measures. In lxml versions up to 4.9.x, external entities are resolved b…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6985">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11341 – A security flaw has been discovered in Jinher OA up to 2.0. This affects an unkn...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11341</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11341</guid>
    <pubDate>Mon, 06 Oct 2025 17:16:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11341</strong></p>
  <p>A security flaw has been discovered in Jinher OA up to 2.0. This affects an unknown function of the file /c6/Jhsoft.Web.module/eformaspx/WebDesign.aspx/?type=SystemUserInfo&style=1. Performing manipulation results in xml external entity reference. Remote exploitation of the attack is possible. The exploit has been released to the public and may be exploited.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11341">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48006 – Improper restriction of XML external entity reference issue exists in DataSpider...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48006</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48006</guid>
    <pubDate>Mon, 29 Sep 2025 08:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48006</strong></p>
  <p>Improper restriction of XML external entity reference issue exists in DataSpider Servista 4.4 and earlier. If a specially crafted request is processed, arbitrary files on the file system where the server application for the product is installed may be read, or a denial-of-service (DoS) condition may occur.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48006">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-11140 – A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11140</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11140</guid>
    <pubDate>Mon, 29 Sep 2025 04:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-11140</strong></p>
  <p>A vulnerability was identified in Bjskzy Zhiyou ERP up to 11.0. Affected by this vulnerability is the function openForm of the component com.artery.richclient.RichClientService. Such manipulation of the argument contentString leads to xml external entity reference. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was contacted early about this d…</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11140">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10816 – A security flaw has been discovered in Jinher OA 2.0. This affects an unknown pa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10816</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10816</guid>
    <pubDate>Mon, 22 Sep 2025 22:15:41 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10816</strong></p>
  <p>A security flaw has been discovered in Jinher OA 2.0. This affects an unknown part of the file /c6/Jhsoft.Web.module/ToolBar/GetWordFileName.aspx/?text=GetUrl&style=add of the component XML Handler. Performing manipulation results in xml external entity reference. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10816">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-10183 – A blind XML External Entity (XXE) injection in the OpenMessaging webservice in T...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10183</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10183</guid>
    <pubDate>Tue, 09 Sep 2025 15:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-10183</strong></p>
  <p>A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised to upgrade to TecCom Connect 5.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10183">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10092 – A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown functi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10092</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10092</guid>
    <pubDate>Mon, 08 Sep 2025 12:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10092</strong></p>
  <p>A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10092">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-10091 – A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-10091</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-10091</guid>
    <pubDate>Mon, 08 Sep 2025 11:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-10091</strong></p>
  <p>A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.projectmanage/ProjectManage/XmlHttp.aspx/?Type=add of the component XML Handler. The manipulation leads to xml external entity reference. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-10091">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-6984 – The langchain-ai/langchain project, specifically the EverNoteLoader component, i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-6984</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-6984</guid>
    <pubDate>Thu, 04 Sep 2025 10:42:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-6984</strong></p>
  <p>The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE) attacks due to insecure XML parsing. The affected version is 0.3.63. The vulnerability arises from the use of etree.iterparse() without disabling external entity references, which can lead to sensitive information disclosure. An attacker could exploit this by crafting a malici…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-6984">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-7307 – Sangfor Behavior Management System (also referred to as DC Management System in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-7307</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-7307</guid>
    <pubDate>Wed, 27 Aug 2025 22:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-7307</strong></p>
  <p>Sangfor Behavior Management System (also referred to as DC Management System in Chinese-language documentation) contains an XML external entity (XXE) injection vulnerability in the /src/sangforindex endpoint. A remote unauthenticated attacker can submit crafted XML data containing external entity definitions, leading to potential disclosure of internal files, server-side request forgery (SSRF), o…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-7307">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54988 – Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54988</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54988</guid>
    <pubDate>Wed, 20 Aug 2025 20:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54988</strong></p>
  <p>Critical XXE in Apache Tika (tika-parser-pdf-module) in Apache Tika 1.13 through and including 3.2.1 on all platforms allows an attacker to carry out XML External Entity injection via a crafted XFA file inside of a PDF. An attacker may be able to read sensitive data or trigger malicious requests to internal resources or third-party servers. Note that the tika-parser-pdf-module is used as a depend…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54988">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4044 – Improper Restriction of XML External Entity Reference in various Lexmark printer...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4044</guid>
    <pubDate>Tue, 19 Aug 2025 14:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4044</strong></p>
  <p>Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54254 – Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54254</guid>
    <pubDate>Tue, 05 Aug 2025 17:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54254</strong></p>
  <p>Adobe Experience Manager versions 6.5.23 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files on the local file system, scope is changed. Exploitation of this issue does not require user interaction.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-19144 – XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19144</guid>
    <pubDate>Fri, 01 Aug 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-19144</strong></p>
  <p>XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-776</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54445 – Improper Restriction of XML External Entity Reference vulnerability in Samsung E...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54445</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54445</guid>
    <pubDate>Wed, 23 Jul 2025 06:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54445</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Server: less than 21.1080.0.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54445">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7766 – Lantronix Provisioning Manager is vulnerable to XML external entity attacks in c...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7766</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7766</guid>
    <pubDate>Tue, 22 Jul 2025 22:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7766</strong></p>
  <p>Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.</p>
  <p><strong>CVSS:</strong> 8.0 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7766">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7824 – A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. Th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7824</guid>
    <pubDate>Sat, 19 Jul 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7824</strong></p>
  <p>A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml external entity reference. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7823 – A vulnerability was found in Jinher OA 1.2. It has been declared as problematic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7823</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7823</guid>
    <pubDate>Sat, 19 Jul 2025 13:15:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7823</strong></p>
  <p>A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation leads to xml external entity reference. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7823">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-53689 – Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apach...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53689</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53689</guid>
    <pubDate>Mon, 14 Jul 2025 10:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-53689</strong></p>
  <p>Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges.  Users are recommended to upgrade to versions 2.20.17 (Java 8), 2.22.1 (Java 11) or 2.23.2 (Java 11, beta versions), which fix this issue. Earlier versions (up to 2.20.16) are not supported anymore, thus users should update to the re…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53689">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-7523 – A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affect...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-7523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-7523</guid>
    <pubDate>Sun, 13 Jul 2025 07:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-7523</strong></p>
  <p>A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.aspx. The manipulation leads to xml external entity reference. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-610</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-7523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-49535 – ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Impr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-49535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-49535</guid>
    <pubDate>Tue, 08 Jul 2025 21:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-49535</strong></p>
  <p>ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Security feature bypass. An attacker could exploit this vulnerability to access sensitive information or denial of service by bypassing security measures. Exploitation of this issue does not require user interaction and scop…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-49535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-52888 – Allure 2 is the version 2.x branch of Allure Report, a multi-language test repor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52888</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52888</guid>
    <pubDate>Tue, 24 Jun 2025 20:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-52888</strong></p>
  <p>Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used by Allure 2 prior to version 2.34.1. The plugin fails to securely configure the XML parser (`DocumentBuilderFactory`) and allows external entity expansion when processing test result .xml files. This allows attackers to r…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52888">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-33121 – IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12  is vulnerable to an XML ext...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-33121</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-33121</guid>
    <pubDate>Thu, 19 Jun 2025 18:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-33121</strong></p>
  <p>IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12  is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-33121">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-36049 – IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15 

is vulnerable t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-36049</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-36049</guid>
    <pubDate>Wed, 18 Jun 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-36049</strong></p>
  <p>IBM webMethods Integration Server 10.5, 10.7, 10.11, and 10.15   is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to execute arbitrary commands.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-36049">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-44044 – Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-44044</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-44044</guid>
    <pubDate>Tue, 10 Jun 2025 16:15:40 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-44044</strong></p>
  <p>Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DTD files can exfiltrate some files from the underlying operating system.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-44044">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-30220 – GeoServer is an open source server that allows users to share and edit geospatia...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30220</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30220</guid>
    <pubDate>Tue, 10 Jun 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-30220</strong></p>
  <p>GeoServer is an open source server that allows users to share and edit geospatial data. GeoTools Schema class use of Eclipse XSD library to represent schema data structure is vulnerable to XML External Entity (XXE) exploit. This impacts whoever exposes XML processing with gt-xsd-core involved in parsing, when the documents carry a reference to an external XML schema. The gt-xsd-core Schemas class…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30220">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-31039 – Improper Restriction of XML External Entity Reference vulnerability in pixelgrad...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31039</guid>
    <pubDate>Mon, 09 Jun 2025 16:15:36 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-31039</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a through <= 1.0.3.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-48882 – PHPOffice Math is a library that provides a set of classes to manipulate differe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48882</guid>
    <pubDate>Fri, 30 May 2025 20:15:43 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-48882</strong></p>
  <p>PHPOffice Math is a library that provides a set of classes to manipulate different formula file formats. Prior to version 0.3.0, loading XML data using the standard `libxml` extension and the `LIBXML_DTDLOAD` flag without additional filtration, leads to XXE. Version 0.3.0 fixes the vulnerability.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27523 – XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27523</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27523</guid>
    <pubDate>Thu, 15 May 2025 07:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27523</strong></p>
  <p>XXE vulnerability in Hitachi JP1/IT Desktop Management 2 - Smart Device Manager on Windows.This issue affects JP1/IT Desktop Management 2 - Smart Device Manager: from 12-00 before 12-00-08, from 11-10 through 11-10-08, from 11-00 through 11-00-05, from 10-50 through 10-50-06.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27523">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-4641 – Improper Restriction of XML External Entity Reference vulnerability in bonigarci...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4641</guid>
    <pubDate>Wed, 14 May 2025 19:15:53 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-4641</strong></p>
  <p>Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on Windows, MacOS, Linux (XML parsing components modules) allows Data Serialization External Entities Blowup. This vulnerability is associated with program files src/main/java/io/github/bonigarcia/wdm/WebDriverManager.java.  This issue affects webdrivermanager: from 1.0.0 before 6.0…</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-4639 – CWE-611 Improper Restriction of XML External Entity Reference in the getDocument...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-4639</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-4639</guid>
    <pubDate>Wed, 14 May 2025 18:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-4639</strong></p>
  <p>CWE-611 Improper Restriction of XML External Entity Reference in the getDocumentBuilder() method of WebDav servlet in Peergos. This issue affects Peergos through version 1.1.0.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-4639">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2777 – SysAid On-Prem versions &lt;= 23.3.40 are vulnerable to an unauthenticated XML Exte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2777</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2777</guid>
    <pubDate>Wed, 07 May 2025 15:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2777</strong></p>
  <p>SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the lshw processing functionality,  allowing for administrator account takeover and file read primitives.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2777">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2776 – SysAid On-Prem versions &lt;= 23.3.40 are vulnerable to an unauthenticated XML Exte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2776</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2776</guid>
    <pubDate>Wed, 07 May 2025 15:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2776</strong></p>
  <p>SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2776">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2775 – SysAid On-Prem versions &lt;= 23.3.40 are vulnerable to an unauthenticated XML Exte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2775</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2775</guid>
    <pubDate>Wed, 07 May 2025 15:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2775</strong></p>
  <p>SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vulnerability in the Checkin processing functionality,  allowing for administrator account takeover and file read primitives.</p>
  <p><strong>CVSS:</strong> 9.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2775">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-22478 – Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Im...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22478</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22478</guid>
    <pubDate>Tue, 06 May 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-22478</strong></p>
  <p>Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entity Reference vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22478">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-2905 – Due to the improper configuration of XML parser, user-supplied XML is parsed wit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-2905</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-2905</guid>
    <pubDate>Mon, 05 May 2025 09:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-2905</strong></p>
  <p>Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, enabling XML External Entity (XXE) resolution in multiple WSO2 Products.  A successful XXE attack could allow a remote, unauthenticated attacker to:   *  Read sensitive files from the server’s filesystem.   *  Perform denial-of-service (DoS) attacks, which can render the affected…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-2905">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-31497 – TEIGarage is a webservice and RESTful service to transform, convert and validate...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-31497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-31497</guid>
    <pubDate>Tue, 15 Apr 2025 20:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-31497</strong></p>
  <p>TEIGarage is a webservice and RESTful service to transform, convert and validate various formats, focussing on the TEI format. The Document Conversion Service contains a critical XML External Entity (XXE) Injection vulnerability in its document conversion functionality. The service processes XML files during the conversion process but fails to disable external entity processing, allowing an attac…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-31497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-32406 – An XXE issue in the Director NBR component in NAKIVO Backup &amp; Replication 10.3.x...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32406</guid>
    <pubDate>Tue, 08 Apr 2025 15:15:50 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-32406</strong></p>
  <p>An XXE issue in the Director NBR component in NAKIVO Backup & Replication 10.3.x through 11.0.1 before 11.0.2 allows remote attackers fetch and parse the XML response.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-25589 – An XML external entity (XXE) injection vulnerability in the component /weixin/ae...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-25589</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-25589</guid>
    <pubDate>Tue, 18 Mar 2025 16:15:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-25589</strong></p>
  <p>An XML external entity (XXE) injection vulnerability in the component /weixin/aes/XMLParse.java of yimioa before v2024.07.04 allows attackers to execute arbitrary code via supplying a crafted XML file.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-91</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-25589">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-0162 – IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external enti...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-0162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-0162</guid>
    <pubDate>Fri, 07 Mar 2025 17:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-0162</strong></p>
  <p>IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-38693 – Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting langu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-38693</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-38693</guid>
    <pubDate>Wed, 05 Mar 2025 16:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-38693</strong></p>
  <p>Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoint is vulnerable to RCE via an XML XXE attack. This vulnerability is fixed in Lucee 5.4.3.2, 5.3.12.1, 5.3.7.59, 5.3.8.236, and 5.3.9.173.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-38693">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-56525 – In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56525</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56525</guid>
    <pubDate>Mon, 24 Feb 2025 23:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-56525</strong></p>
  <p>In Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can create a new role as super admin in the journal context, and insert a backdoor plugin, by uploading a crafted XML document as a User XML Plugin.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56525">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49781 – IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML exte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49781</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49781</guid>
    <pubDate>Thu, 20 Feb 2025 12:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49781</strong></p>
  <p>IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49781">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-47160 – IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 





...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47160</guid>
    <pubDate>Wed, 19 Feb 2025 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-47160</strong></p>
  <p>IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0       is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 8.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-54171 – IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-54171</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-54171</guid>
    <pubDate>Thu, 06 Feb 2025 21:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-54171</strong></p>
  <p>IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-54171">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-49352 – IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49352</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49352</guid>
    <pubDate>Wed, 05 Feb 2025 11:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-49352</strong></p>
  <p>IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49352">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52807 – The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52807</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52807</guid>
    <pubDate>Fri, 24 Jan 2025 19:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52807</strong></p>
  <p>The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag `( ]>` could produce XML containing data from the host system. This impacts use cases where org.hl7.fhir.publisher is being used to within a…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52807">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-23195 – An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie 
project, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23195</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23195</guid>
    <pubDate>Tue, 21 Jan 2025 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-23195</strong></p>
  <p>An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie  project, allowing an attacker to inject malicious XML entities. This  vulnerability occurs due to insecure parsing of XML input using the  `DocumentBuilderFactory` class without disabling external entity  resolution. An attacker can exploit this vulnerability to read arbitrary  files on the server or perform server-side reques…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23195">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-12476 – CWE-611: Improper Restriction of XML External Entity Reference vulnerability exi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-12476</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-12476</guid>
    <pubDate>Fri, 17 Jan 2025 10:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-12476</strong></p>
  <p>CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on the compromised computer, when specific crafted XML file is imported in the Web Designer configuration tool.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-12476">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-35532 – An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35532</guid>
    <pubDate>Tue, 07 Jan 2025 20:15:29 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-35532</strong></p>
  <p>An XML External Entity (XXE) injection vulnerability in Intersec Geosafe-ea 2022.12, 2022.13, and 2022.14 allows attackers to perform arbitrary file reading under the privileges of the running process, make SSRF requests, or cause a Denial of Service (DoS) via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-125</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46603 – An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Faul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46603</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46603</guid>
    <pubDate>Tue, 07 Jan 2025 16:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46603</strong></p>
  <p>An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of Service (DoS) via a crafted XML payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46603">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-46602 – An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46602</guid>
    <pubDate>Tue, 07 Jan 2025 16:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-46602</strong></p>
  <p>An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an attacker to cause a Denial of Service (DoS) via a crafted XML payload.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56324 – GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56324</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56324</guid>
    <pubDate>Fri, 03 Jan 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56324</strong></p>
  <p>GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration for groups they administer to trigger XML External Entity (XXE) injection on the GoCD server. Theoretically, the XXE vulnerability can result in additional attacks such as SSRF, information disclosure from the GoCD server, and directory traversal, alt…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56324">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-56322 – GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclus...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-56322</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-56322</guid>
    <pubDate>Fri, 03 Jan 2025 16:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-56322</strong></p>
  <p>GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration repository (pipelines as code) feature to allow XML External Entity (XXE) injection on the GoCD Server which will be executed when GoCD periodically scans configuration repositories for pipeline updates, or is triggered by an administrator or config rep…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-56322">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-40896 – In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-40896</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-40896</guid>
    <pubDate>Mon, 23 Dec 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-40896</strong></p>
  <p>In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX handlers try to override entity content (by setting "checked"). This makes classic XXE attacks possible.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-40896">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55081 – An XML External Entity (XXE) injection vulnerability in the component /datagrip/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55081</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55081</guid>
    <pubDate>Thu, 19 Dec 2024 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55081</strong></p>
  <p>An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code via supplying a crafted XML input.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55081">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55887 – Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55887</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55887</guid>
    <pubDate>Fri, 13 Dec 2024 16:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55887</strong></p>
  <p>Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag could produce XML containing data from the host system. This impacts use cases where ucum is being used to within a host where external clients can submit XML. Release 1.…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55887">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-55875 – http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55875</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55875</guid>
    <pubDate>Thu, 12 Dec 2024 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-55875</strong></p>
  <p>http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 5.41.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling malicious XML contents within requests, which might allow attackers to read local sensitive information on server, trigger Server-side Request Forgery and even execute code under some circumstances. Version 5.41.0.0 con…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55875">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-46455 – unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-46455</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-46455</guid>
    <pubDate>Mon, 09 Dec 2024 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-46455</strong></p>
  <p>unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-46455">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52806 – SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Wh...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52806</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52806</guid>
    <pubDate>Mon, 02 Dec 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52806</strong></p>
  <p>SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. This vulnerability is fixed in 4.6.14 and 5.0.0-alpha.18.</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52806">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
