Skip to main content

CWE archive

CWE-776 CVEs

Programmatic archive

86 CVEs tagged with CWE-7766 Critical, 42 High, 38 Medium, 0 Low, 0 Unrated.

CVE-2026-14865

Published Jul 22, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated de…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-14979

Published Jul 17, 2026

IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 DOOR…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-45304

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser resolv…

CVSS 8.7 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-45133

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attack…

CVSS 8.2 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-44018

Published Jun 26, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML…

CVSS 5.5 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-12993

Published Jun 26, 2026

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECU…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-44020

Published Jun 24, 2026

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.13.0 until 2.74.0, the USPTO patent XML parse…

CVSS 7.5 · High
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2026-45771

Published Jun 9, 2026

FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardwa…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-23822

Published May 12, 2026

A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to trigger a denial-of-service condition. Successful exploitati…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2026-31248

Published May 11, 2026

Docling's METS GBS backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend extracts and validates XML files from .tar.gz archives using etree.fromstri…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5

CVE-2026-42212

Published May 8, 2026

SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the Solid…

CVSS 7.1 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-41673

Published May 7, 2026

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom vers…

CVSS 8.7 · High
evidence mentions
17
Buzz score
46.9

CVE-2026-40260

Published Apr 17, 2026

pypdf is a free and open-source pure-python PDF library. In versions prior to 6.10.0, manipulated XMP metadata entity declarations can exhaust RAM. An attacker who exploits this v…

CVSS 6.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-33908

Published Apr 13, 2026

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, Magick frees the memory of the XML tr…

CVSS 7.5 · High
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort

CVE-2026-33036

Published Mar 20, 2026

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where num…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-29074

Published Mar 6, 2026

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 2.1.0 to before version 2.8.1, from version 3.0.0 to before…

CVSS 7.5 · High
evidence mentions
28
Buzz score
43.0
Vendor/product tagsBeta · best-effort

CVE-2026-27807

Published Mar 6, 2026

MarkUs is a web application for the submission and grading of student assignments. Prior to version 2.9.4, MarkUs allows course instructors to upload YAML files to create/update v…

CVSS 4.9 · Medium
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-26278

Published Feb 19, 2026

fast-xml-parser allows users to validate XML, parse XML to JS object, or build XML from JS object without C/C++ based libraries and no callback. In versions 4.1.3 through 5.3.5, t…

CVSS 7.5 · High
evidence mentions
13
Buzz score
39.4
Vendor/product tagsBeta · best-effort

CVE-2019-19144

Published Aug 1, 2025

XML External Entity Injection vulnerability in Quantum DXi6702 2.3.0.3 (11449-53631 Build304) devices via rest/Users?action=authenticate.

CVSS 9.8 · Critical

CVE-2025-3225

Published Jul 7, 2025

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting versio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-0617

Published Jan 29, 2025

An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing contain…

CVSS 5.9 · Medium
evidence mentions
1
Buzz score
11.9
Showing 1-25 of 86 CVEsPage 1 of 4