Vulnerabilities in NaturalIntelligence
11 resultsVexday analysis
NaturalIntelligence apresenta 11 vulnerabilidades catalogadas, com 1 crítica e 3 publicadas nos últimos 90 dias, indicando atividade recente de descobertas. Nenhuma vulnerabilidade está sob exploração ativa confirmada (KEV), reduzindo o risco imediato. A fraqueza dominante é CWE-91 (XML External Entity - XXE), padrão em processamento de dados estruturados, requerendo revisão de protocolos de validação de entrada.
CVE-2023-34104HIGHRegex Injection via Doctype EntitiesEPSS 1.1%CVE-2026-26278HIGHfast-xml-parser affected by DoS through entity expansion in DOCTYPE (no expansion limit)EPSS 0.8%CVE-2024-41818HIGHReDOS at currency parsing fast-xml-parserEPSS 0.8%CVE-2026-33036HIGHfast-xml-parser affected by numeric entity expansion bypassing all entity expansion limits (incomplete fix for CVE-2026-26278)EPSS 0.6%CVE-2026-25128HIGHfast-xml-parser has RangeError DoS Numeric Entities BugEPSS 0.6%CVE-2026-27942LOWfast-xml-parser has stack overflow in XMLBuilder with preserveOrderEPSS 0.5%CVE-2026-25896CRITICALfast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity namesEPSS 0.5%CVE-2026-33349MEDIUMfast-xml-parser: Entity Expansion Limits Bypassed When Set to Zero Due to JavaScript Falsy EvaluationEPSS 0.4%CVE-2026-41650MEDIUMfast-xml-parser XMLBuilder: XML Comment and CDATA Injection via Unescaped DelimitersEPSS 0.2%CVE-2026-44665MEDIUMfast-xml-builder: Attribute values with unwanted quotes can bypass malicious or unwanted attributesEPSS 0.2%CVE-2026-44664MEDIUMfast-xml-builder: Comment Value bypass regexEPSS 0.2%