Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-611Definition on MITRE ↗Clear

8 results

CVE-2025-58360
2025-12-11
OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability
OSGeo

OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.

CWE-611
RefsThis vulnerability affects an open-source component, third-party library, or a protocol used by different products. For more information, please seeosgeo-org.atlassian.netnvd.nist.gov
Federal remediation due 2026-01-01
CVE-2025-2776
2025-07-22
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
SysAid

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read primitives.

CWE-611
Refsdocumentation.sysaid.comnvd.nist.gov
Federal remediation due 2025-08-12
CVE-2025-2775
2025-07-22
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
SysAid

SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primitives.

CWE-611
Refsdocumentation.sysaid.comnvd.nist.gov
Federal remediation due 2025-08-12
CVE-2023-45727
2024-12-03
North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability
North Grid

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

CWE-611
Refsproself.jpnvd.nist.gov
Federal remediation due 2024-12-24
CVE-2024-34102
2024-07-17
Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Adobe

Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.

CWE-611
Refshelpx.adobe.comnvd.nist.gov
Federal remediation due 2024-08-07
CVE-2019-9670
2022-01-10
Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference
Synacor

Synacor Zimbra Collaboration Suite (ZCS) contains an improper restriction of XML external entity (XXE) vulnerability in the mailboxd component.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-07-10
CVE-2019-13608
2021-11-03
Citrix StoreFront Server XML External Entity (XXE) Processing VulnerabilityRansomware
Citrix

Citrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-05-03
CVE-2016-9563
2021-11-03
SAP NetWeaver XML External Entity (XXE) Vulnerability
SAP

SAP NetWeaver Application Server Java Platforms contains an unspecified vulnerability in BC-BMT-BPM-DSK which allows remote, authenticated users to conduct XML External Entity (XXE) attacks.

CWE-611
Refsnvd.nist.gov
Federal remediation due 2022-05-03