CVE.report search for "Xml"
Listed below are 50 relevant search results for "Xml" based on Vendor, Software, and CVE description
These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.
If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.
Search Results
| CVE ID | Vendor | Software | Description |
|---|---|---|---|
| CVE-2026-34401 | Microsoft | Xml Notepad | XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prio... |
| CVE-2026-21999 | Oracle | Xml Database | Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26... |
| CVE-2026-11979 | Xmlsoft | Libxml2 | libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The us... |
| CVE-2026-6732 | Xmlsoft | Libxml2 | A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (... |
| CVE-2026-6653 | Xmlsoft | Libxml2 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to ca... |
| CVE-2026-0989 | Xmlsoft | Libxml2 | A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does... |
| CVE-2025-9714 | Xmlsoft | Libxml2 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to cause a... |
| CVE-2025-8732 | Xmlsoft | Libxml2 | A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the functi... |
| CVE-2025-7424 | Xmlsoft | Libxslt | A flaw was found in the libxslt library. The same memory field, psvi, is used for both stylesheet and input data, which can l... |
| CVE-2025-6170 | Xmlsoft | Libxml2 | A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an... |
| CVE-2025-6021 | Xmlsoft | Libxml2 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack... |
| CVE-2023-49087 | Simplesamlphp | Xml-security | |
| CVE-2023-45322 | Xmlsoft | Libxml2 | ** DISPUTED ** libxml2 through 2.11.5 has a use-after-free that can only occur after a certain memory allocation fails. This ... |
| CVE-2023-39643 | Blmodules | Xmlfeeds Pro | Bl Modules xmlfeeds before v3.9.8 was discovered to contain a SQL injection vulnerability via the component SearchApiXml::Xml... |
| CVE-2023-39615 | Xmlsoft | Libxml2 | ** DISPUTED ** Xmlsoft Libxml2 v2.11.0 was discovered to contain an out-of-bounds read via the xmlSAX2StartElement() function... |
| CVE-2023-36661 | Shibboleth | Xmltooling | Shibboleth XMLTooling before 3.2.4, as used in OpenSAML and Shibboleth Service Provider, allows SSRF via a crafted KeyInfo el... |
| CVE-2023-34411 | Xml Library Project | Xml Library | The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid |
| CVE-2023-30877 | Icopydoc | Xml For Google Merchant Center | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maxim Glazunov XML for Google Merchant Center plugin <= 3.0.1 ... |
| CVE-2023-29469 | Xmlsoft | Libxml2 | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFa... |
| CVE-2023-28484 | Xmlsoft | Libxml2 | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a se... |
| CVE-2023-0842 | Xml2js Project | Xml2js | xml2js version 0.4.23 allows an external attacker to edit or add new properties to an object. This is possible because the ap... |
| CVE-2022-47514 | Xml-rpc.net Project | Xml-rpc.net | An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct... |
| CVE-2022-44730 | Apache | Xml Graphics Batik | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects A... |
| CVE-2022-44729 | Apache | Xml Graphics Batik | Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects A... |
| CVE-2022-40304 | Xmlsoft | Libxml2 | An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potent... |
| CVE-2022-40303 | Xmlsoft | Libxml2 | An issue was discovered in libxml2 before 2.10.3. When parsing a multi-gigabyte XML document with the XML_PARSE_HUGE parser o... |
| CVE-2022-39353 | Xmldom Project | Xmldom | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. xmldom parses X... |
| CVE-2022-37616 | Xmldom Project | Xmldom | A prototype pollution vulnerability exists in the function copy in dom.js in the xmldom (published as @xmldom/xmldom) package... |
| CVE-2022-29824 | Xmlsoft | Libxml2 | In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for intege... |
| CVE-2022-23308 | Xmlsoft | Libxml2 | valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
| CVE-2022-2309 | Xmlsoft | Libxml2 | NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is... |
| CVE-2022-0346 | Xmlsitemapgenerator | Xml Sitemap Generator | The XML Sitemap Generator for Google WordPress plugin before 2.0.4 does not validate a parameter which can be set to an arbit... |
| CVE-2021-40690 | Apache | Xml Security For Java | All versions of Apache Santuario - XML Security for Java prior to 2.2.3 and 2.1.7 are vulnerable to an issue where the "secur... |
| CVE-2021-32796 | Xmldom Project | Xmldom | xmldom is an open source pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom... |
| CVE-2021-31597 | Xmlhttprequest-ssl Project | Xmlhttprequest-ssl | The xmlhttprequest-ssl package before 1.6.1 for Node.js disables SSL certificate validation by default, because rejectUnautho... |
| CVE-2021-30560 | Xmlsoft | Libxslt | Use after free in Blink XSLT in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially exploit heap co... |
| CVE-2021-25951 | Xml2dict Project | Xml2dict | XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service. |
| CVE-2021-23926 | Apache | Xmlbeans | The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML... |
| CVE-2021-21366 | Xmldom Project | Xmldom | xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. xmldom versions 0.4... |
| CVE-2021-20845 | Xml-sitemaps | Unlimited Sitemap Generator | Cross-site request forgery (CSRF) vulnerability in Unlimited Sitemap Generator versions prior to v8.2 allows a remote attacke... |
| CVE-2021-4249 | Haskell | Xml-conduit | A vulnerability was found in xml-conduit. It has been classified as problematic. Affected is an unknown function of the file ... |
| CVE-2021-3666 | Xml Body Parser Project | Xml Body Parser | body-parser-xml is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') |
| CVE-2021-3541 | Xmlsoft | Libxml2 | A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all existing protection mechanisms an... |
| CVE-2021-3537 | Xmlsoft | Libxml2 | A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed con... |
| CVE-2021-3518 | Xmlsoft | Libxml2 | There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an a... |
| CVE-2021-3517 | Xmlsoft | Libxml2 | There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to sup... |
| CVE-2021-3516 | Xmlsoft | Xmllint | There's a flaw in libxml2's xmllint in versions before 2.9.11. An attacker who is able to submit a crafted file to be process... |
| CVE-2021-2333 | Oracle | Xml Database | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12... |
| CVE-2021-2329 | Oracle | Xml Database | Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12... |
| CVE-2020-28502 | Xmlhttprequest Project | Xmlhttprequest | This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent ... |