Skip to content
Noroxi

lxml records

7 published records for vendor lxml.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

7 records
  • CVE-2022-2309
    31Monitor

    NULL Pointer Dereference in lxml/lxml

    HighCVSS 7.5No exploitEPSS 2%

    lxml · lxmlJul 5, 2022

  • lxml: Default configuration of iterparse() and ETCompatXMLParser() allows XXE to local files

    HighCVSS 7.5No exploitEPSS 0%

    lxml · lxmlApr 24, 2026

  • HTML Cleaner allows crafted and SVG embedded scripts to pass through

    HighCVSS 7.1No exploitEPSS 2%

    lxml · lxmlDec 13, 2021

  • CVE-2014-3146
    26Monitor

    Incomplete blacklist vulnerability in the lxml.html.clean module in lxml before 3.3.5 allows remote attackers to conduct cross-site scriptin

    MediumCVSS 6.1Proof of conceptEPSS 6%

    lxml · lxmlMay 14, 2014

  • An XSS vulnerability was discovered in python-lxml's clean module versions before 4.6.3.

    MediumCVSS 6.1No exploitEPSS 4%

    lxml · lxmlMar 21, 2021

  • A XSS vulnerability was discovered in python-lxml's clean module.

    MediumCVSS 6.1No exploitEPSS 4%

    lxml · lxmlDec 3, 2020

  • An issue was discovered in lxml before 4.2.5.

    MediumCVSS 6.1No exploitEPSS 2%

    lxml · lxmlDec 2, 2018