Vulnerabilities > Apache > Any23 > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-05 CVE-2022-25312 XXE vulnerability in Apache Any23
An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions < 2.7.
network
low complexity
apache CWE-611
critical
9.1
2021-09-11 CVE-2021-40146 Unspecified vulnerability in Apache Any23
A Remote Code Execution (RCE) vulnerability was discovered in the Any23 YAMLExtractor.java file and is known to affect Any23 versions < 2.5.
network
low complexity
apache
critical
9.8
2021-09-11 CVE-2021-38555 XXE vulnerability in Apache Any23
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5.
network
low complexity
apache CWE-611
critical
9.1