7 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-54078 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve | HIGH | 8.7 | 24%ile | NVD | 2026-07-29 |
| CVE-2026-54079 | veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30 | HIGH | 8.7 | 24%ile | NVD | 2026-07-29 |
| CVE-2026-54366 | CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attack | HIGH | 8.7 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-50782 | Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manage | HIGH | 7.5 | 28%ile | NVD | 2026-07-29 |
| CVE-2026-41066 | lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files | HIGH | 7.5 | 25%ile | Microsoft | 2026-04-14 |
| CVE-2026-54082 | veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, ve | MEDIUM | 6.5 | 14%ile | NVD | 2026-07-29 |
| CVE-2025-36374 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile | MEDIUM | 5.5 | 15%ile | NVD | 2026-07-30 |