CVE.report search for "Xml"

Listed below are 50 relevant search results for "Xml" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-34401MicrosoftXml NotepadXML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prio...
CVE-2026-21999OracleXml DatabaseVulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26...
CVE-2026-11979XmlsoftLibxml2libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The us...
CVE-2026-6732XmlsoftLibxml2A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (...
CVE-2026-6653XmlsoftLibxml2Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to ca...
CVE-2026-0989XmlsoftLibxml2A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does...
CVE-2025-9714XmlsoftLibxml2Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a...
CVE-2025-8732XmlsoftLibxml2A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the functi...
CVE-2025-7424XmlsoftLibxsltA flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can l...
CVE-2025-6170XmlsoftLibxml2A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an...
CVE-2025-6021XmlsoftLibxml2A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack...
CVE-2023-49087SimplesamlphpXml-security
CVE-2023-45322XmlsoftLibxml2** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This ...
CVE-2023-39643BlmodulesXmlfeeds ProBl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xml...
CVE-2023-39615XmlsoftLibxml2** DISPUTED ** Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function...
CVE-2023-36661ShibbolethXmltoolingShibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo el...
CVE-2023-34411Xml Library ProjectXml LibraryThe xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid
CVE-2023-30877IcopydocXml For Google Merchant CenterUnauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 ...
CVE-2023-29469XmlsoftLibxml2An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFa...
CVE-2023-28484XmlsoftLibxml2In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a se...
CVE-2023-0842Xml2js ProjectXml2jsxml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the ap...
CVE-2022-47514Xml-rpc.net ProjectXml-rpc.netAn XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct...
CVE-2022-44730ApacheXml Graphics BatikServer-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects A...
CVE-2022-44729ApacheXml Graphics BatikServer-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects A...
CVE-2022-40304XmlsoftLibxml2An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potent...
CVE-2022-40303XmlsoftLibxml2An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser o...
CVE-2022-39353Xmldom ProjectXmldomxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses X...
CVE-2022-37616Xmldom ProjectXmldomA prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package...
CVE-2022-29824XmlsoftLibxml2In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for intege...
CVE-2022-23308XmlsoftLibxml2valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
CVE-2022-2309XmlsoftLibxml2NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is...
CVE-2022-0346XmlsitemapgeneratorXml Sitemap GeneratorThe XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbit...
CVE-2021-40690ApacheXml Security For JavaAll versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secur...
CVE-2021-32796Xmldom ProjectXmldomxmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom...
CVE-2021-31597Xmlhttprequest-ssl ProjectXmlhttprequest-sslThe xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnautho...
CVE-2021-30560XmlsoftLibxsltUse after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap co...
CVE-2021-25951Xml2dict ProjectXml2dictXXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
CVE-2021-23926ApacheXmlbeansThe XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML...
CVE-2021-21366Xmldom ProjectXmldomxmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4...
CVE-2021-20845Xml-sitemapsUnlimited Sitemap GeneratorCross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacke...
CVE-2021-4249HaskellXml-conduitA vulnerability was found in xml-conduit. It has been classified as problematic. Affected is an unknown function of the file ...
CVE-2021-3666Xml Body Parser ProjectXml Body Parserbody-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
CVE-2021-3541XmlsoftLibxml2A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms an...
CVE-2021-3537XmlsoftLibxml2A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed con...
CVE-2021-3518XmlsoftLibxml2There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an a...
CVE-2021-3517XmlsoftLibxml2There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to sup...
CVE-2021-3516XmlsoftXmllintThere's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be process...
CVE-2021-2333OracleXml DatabaseVulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12...
CVE-2021-2329OracleXml DatabaseVulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12...
CVE-2020-28502Xmlhttprequest ProjectXmlhttprequestThis affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent ...

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report