← All weakness types
XML External Entity (XXE)
CWE-6111,260 vulnerabilities are classified as XML External Entity (XXE) (CWE-611). The most exploitable are shown first (by EPSS), each with its CVSS score, exploit-prediction, CISA KEV status, and available fix.
| CVE | Severity | CVSS | EPSS | Exploited | Fix |
|---|---|---|---|---|---|
| CVE-2024-34102 | Critical | 9.8 | 100% | KEV | Fix |
| CVE-2019-9670 | Critical | 9.8 | 100% | KEV | Fix |
| CVE-2022-28219 | Critical | 9.8 | 97% | - | - |
| CVE-2024-22024 | High | 8.3 | 95% | - | - |
| CVE-2024-38653 | High | 7.5 | 92% | - | - |
| CVE-2017-12629 | Critical | 9.8 | 92% | - | Fix |
| CVE-2013-6429 | Medium | 6.8 | 90% | - | Fix |
| CVE-2021-29447 | High | 7.1 | 86% | - | Fix |
| CVE-2025-54254 | High | 8.6 | 86% | - | - |
| CVE-2022-2414 | High | 7.5 | 85% | - | Fix |
| CVE-2021-2401 | Medium | 5.3 | 85% | - | - |
| CVE-2024-53675 | High | 7.3 | 84% | - | Fix |
| CVE-2023-44412 | High | 8.2 | 84% | - | - |
| CVE-2025-66516 | High | 8.4 | 80% | - | Fix |
| CVE-2025-2777 | Critical | 9.3 | 79% | - | - |
| CVE-2020-17408 | High | 7.5 | 74% | - | - |
| CVE-2020-27858 | High | 7.5 | 74% | - | - |
| CVE-2020-11991 | High | 7.5 | 73% | - | - |
| CVE-2025-2776 | Critical | 9.3 | 73% | KEV | - |
| CVE-2016-4264 | High | 8.6 | 69% | - | - |
| CVE-2025-58360 | High | 8.2 | 67% | KEV | Fix |
| CVE-2021-37425 | Critical | 9.1 | 66% | - | Fix |
| CVE-2020-15419 | High | 7.5 | 64% | - | Fix |
| CVE-2024-37397 | High | 8.2 | 59% | - | Fix |
| CVE-2025-2775 | Critical | 9.3 | 55% | KEV | - |
| CVE-2024-30043 | Medium | 6.5 | 55% | - | Fix |
| CVE-2022-38419 | High | 7.5 | 53% | - | - |
| CVE-2025-30220 | Critical | 9.9 | 51% | - | Fix |
| CVE-2012-3363 | Critical | 9.1 | 50% | - | Fix |
| CVE-2018-1285 | Critical | 9.8 | 50% | - | Fix |
| CVE-2018-8420 | High | 8.8 | 49% | - | - |
| CVE-2024-53674 | High | 7.3 | 47% | - | Fix |
| CVE-2021-21672 | Medium | 4.3 | 43% | - | - |
| CVE-2018-2392 | High | 7.5 | 41% | - | - |
| CVE-2019-7442 | Critical | 9.8 | 40% | - | - |
| CVE-2021-21642 | High | 8.1 | 38% | - | - |
| CVE-2019-9757 | High | 7.5 | 37% | - | - |
| CVE-2022-42341 | High | 7.5 | 36% | - | - |
| CVE-2024-6893 | High | 7.5 | 33% | - | - |
| CVE-2018-13415 | Critical | 9.8 | 32% | - | - |
| CVE-2020-4463 | High | 8.2 | 32% | - | - |
| CVE-2025-11700 | High | 7.5 | 31% | - | Fix |
| CVE-2019-13608 | High | 7.5 | 30% | KEV + Ransom | Fix |
| CVE-2009-1699 | High | 7.5 | 29% | - | Fix |
| CVE-2018-15531 | Critical | 9.8 | 28% | - | Fix |
| CVE-2020-24589 | Critical | 9.1 | 27% | - | - |
| CVE-2017-3548 | Medium | 6.5 | 26% | - | - |
| CVE-2021-30201 | High | 7.5 | 25% | - | Fix |
| CVE-2018-18980 | High | 7.5 | 25% | - | Fix |
| CVE-2019-8086 | High | 7.5 | 24% | - | - |
| CVE-2019-13358 | High | 7.5 | 24% | - | Fix |
| CVE-2016-9563 | Medium | 6.5 | 24% | KEV | - |
| CVE-2018-8533 | Medium | 5.5 | 23% | - | - |
| CVE-2018-8532 | Medium | 5.5 | 23% | - | - |
| CVE-2018-8527 | Medium | 5.5 | 23% | - | - |
| CVE-2025-68493 | High | 8.1 | 23% | - | Fix |
| CVE-2018-8494 | High | 8.8 | 22% | - | - |
| CVE-2018-0878 | Low | 3.1 | 22% | - | - |
| CVE-2019-0795 | High | 8.8 | 21% | - | - |
| CVE-2018-1308 | High | 7.5 | 21% | - | Fix |
| CVE-2018-13417 | Critical | 9.8 | 21% | - | - |
| CVE-2018-13416 | Critical | 9.8 | 20% | - | - |
| CVE-2022-43473 | Medium | 5.8 | 20% | - | Fix |
| CVE-2021-33813 | High | 7.5 | 19% | - | Fix |
| CVE-2013-0340 | Medium | 6.8 | 19% | - | Fix |
| CVE-2021-27931 | Critical | 9.1 | 19% | - | Fix |
| CVE-2018-10613 | High | 7.5 | 18% | - | - |
| CVE-2018-2393 | High | 7.5 | 18% | - | - |
| CVE-2020-25649 | High | 7.5 | 18% | - | Fix |
| CVE-2019-0793 | High | 8.8 | 17% | - | - |
| CVE-2019-0792 | High | 8.8 | 17% | - | - |
| CVE-2019-0791 | High | 8.8 | 17% | - | - |
| CVE-2019-10172 | High | 7.5 | 17% | - | Fix |
| CVE-2018-1247 | High | 7.1 | 17% | - | - |
| CVE-2014-0030 | Critical | 9.8 | 17% | - | - |
| CVE-2018-14485 | Critical | 9.8 | 16% | - | - |
| CVE-2019-0790 | High | 8.8 | 16% | - | - |
| CVE-2019-13990 | Critical | 9.8 | 16% | - | Fix |
| CVE-2011-3600 | High | 7.5 | 16% | - | - |
| CVE-2018-1821 | High | 7.1 | 16% | - | Fix |
| CVE-2018-11586 | Critical | 9.8 | 15% | - | - |
| CVE-2016-3974 | Critical | 9.1 | 15% | - | - |
| CVE-2005-1306 | High | 7.5 | 15% | - | - |
| CVE-2022-22835 | Medium | 6.5 | 14% | - | Fix |
| CVE-2019-15637 | High | 8.1 | 14% | - | - |
| CVE-2018-12463 | Critical | 9.8 | 14% | - | - |
| CVE-2012-0037 | Medium | 6.5 | 14% | - | Fix |
| CVE-2022-36969 | High | 7.1 | 14% | - | Fix |
| CVE-2019-10266 | High | 7.5 | 13% | - | Fix |
| CVE-2017-11272 | High | 7.5 | 13% | - | - |
| CVE-2019-1060 | High | 8.8 | 13% | - | - |
| CVE-2011-4107 | Medium | 6.5 | 13% | - | Fix |
| CVE-2019-0948 | Medium | 4.7 | 13% | - | - |
| CVE-2019-0756 | High | 8.8 | 12% | - | - |
| CVE-2020-8540 | Critical | 9.8 | 12% | - | Fix |
| CVE-2015-7241 | Critical | 9.8 | 12% | - | - |
| CVE-2019-17554 | Medium | 5.5 | 12% | - | - |
| CVE-2015-1832 | Critical | 9.1 | 12% | - | Fix |
| CVE-2012-4399 | High | 7.5 | 12% | - | Fix |
| CVE-2010-2245 | High | 7.4 | 12% | - | - |
Showing the top 100 of 1,260. Browse all 1,260 in the lookup tool.