VulnSea

CWE-611

CVEs classified under CWE-611, newest first.

78 CVEsRSS

CVE-2026-40682Critical· 9.1
4mo ago

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a static SAXParserFa…

▾ Midnightapache · opennlpEPSS 0.84%via NVD
CVE-2025-14543Critical· 9.1
5mo ago

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows Serialized Data External Linking. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before…

▾ Midnightrti · connext_professionalEPSS 0.21%via NVD
CVE-2026-22016High· 7.5PoC
5mo ago

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP)

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affected are Oracle Java SE: 8u481, 8u481-b50, 8u481-perf, 11.0.30, …

▾ Midnightoracle · jreEPSS 0.70%via NVD
CVE-2026-26171High· 7.5
5mo ago

.NET Denial of Service Vulnerability

Uncontrolled resource consumption in .NET allows an unauthorized attacker to deny service over a network.

▾ TwilightMicrosoft · .NET 10.0EPSS 2.3%via CVEORG
CVE-2026-4374Critical· 9.1
5mo ago

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking,…

▾ Midnightrti · connext_professionalEPSS 0.39%via NVD
CVE-2026-34401Medium· 6.5
6mo ago

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are …

▾ Sunlitmicrosoft · xml_notepadEPSS 1.4%via NVD
CVE-2026-28809Medium· 5.3
6mo ago

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messa…

XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messa…

▾ Sunlitarekinath · esamlEPSS 0.45%via NVD
CVE-2025-68493High· 8.1PoC
8mo ago

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

Missing XML Validation vulnerability in Apache Struts, Apache Struts. This issue affects Apache Struts: from 2.0.0 before 2.2.1; Apache Struts: from 2.2.1 through 6.1.0. Users are recommended to upgrade to version 6.1.1, which fixes th…

▾ Midnightapache · strutsEPSS 46%via NVD
CVE-2025-61823Medium· 6.2
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. A high privileged attacker could explo…

▾ Sunlitadobe · coldfusionEPSS 0.49%via NVD
CVE-2025-61813High· 7.4
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnera…

▾ Twilightadobe · coldfusionEPSS 0.55%via NVD
CVE-2025-61821Medium· 6.8
9mo ago

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read

ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnera…

▾ Sunlitadobe · coldfusionEPSS 0.53%via NVD
CVE-2021-45024Critical· 9.8
4y ago

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

▾ Midnightrocketsoftware · ags-zenaEPSS 1.1%via NVD
CVE-2020-25912Critical· 9.1
4y ago

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).

▾ Midnightgetsymphony · symphonyEPSS 1.4%via NVD
CVE-2020-25649High· 7.5
5y ago

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

▾ Twilightfasterxml · jackson-databindEPSS 17%via NVD
CVE-2020-10683Critical· 9.8
6y ago

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is popular external documentation from OWASP showing how to enable the safe, non-default beha…

▾ Midnightdom4j_project · dom4jEPSS 7.3%via NVD
CVE-2019-3773Critical· 9.8
7y ago

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

▾ Midnightbroadcom · spring_web_servicesEPSS 4.1%via NVD
CVE-2019-3774Critical· 9.8
7y ago

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.

▾ Midnightbroadcom · spring_batchEPSS 3.0%via NVD
CVE-2018-1259High· 7.5PoC
8y ago

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity refer…

▾ Midnightbroadcom · spring_data_commonsEPSS 4.9%via NVD
CWE-611 vulnerabilities (CVEs) — page 3 · VulnSea