Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
XXE Denial of Service via RadLayoutBuilder Client State in Telerik UI for ASP.NET AJAX
IBM Engineering Lifecycle Management - Jazz Foundation is vulnerable to XML Entity Expansion attack
Symfony: YAML Parser Exponential Memory Allocation via Recursive Collection-Alias Expansion ("Billion Laughs")
Symfony: [Yaml] Harden the parser when handling untrusted input
Docling: Unsafe Archive Extraction and XML Parsing in METS-GBS Backend
Apicurio/apicurio-registry: apicurio-registry: xml entity-expansion denial of service via internal dtd subset
Docling: Unsafe XML Entity Expansion in USPTO Patent Backend
Freeswitch Denial-of-Service in SIP PUBLISH Requests via XML Entity Expansion
SolidCAM-GPPL-IDE: XML External Entity (XXE) and billion-laughs DoS in VMID parser
pypdf: Manipulated XMP metadata entity declarations can exhaust RAM
fast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)
SVGO: DoS through entity expansion in DOCTYPE (Billion Laughs)
MarkUs: YAML alias (‘billion laughs’) DoS in config upload
fast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)
Extensible Markup Language (XML) External Entity Injection (XXE) through Dashboard label field on Splunk Enterprise
XEE in Ivanti Connect Secure before 22
XML Entity Expansion vulnerability in run-llama/llama_index
An attacker with access to an HX 10
REXML denial of service vulnerability
Hitachi Vantara Pentaho Business Analytics Server - Improper Restriction of XML External Entity Reference
Showing 1 - 20 of 1,000+ results