Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51601

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51602

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51604

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Viewpower HIGH 7.5
CVE-2023-51591

Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attack…

Mitigation only
Fix from $1,950 2024-05-03
D View 8 HIGH 8.2
CVE-2023-44412EPSS 84%

D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose…

Mitigation only
Fix from $1,950 2024-05-03
Myconnection Server MEDIUM 6.5
CVE-2023-42035

Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attac…

Mitigation only
Fix from $1,600 2024-05-03
Simple Editor HIGH 7.5
CVE-2023-40506

LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl…

Mitigation only
Fix from $1,950 2024-05-03
Simple Editor HIGH 7.5
CVE-2023-40507

LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl…

Mitigation only
Fix from $1,950 2024-05-03
Simple Editor HIGH 7.5
CVE-2023-40503

LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl…

Mitigation only
Fix from $1,950 2024-05-03
Ignition MEDIUM 6.5
CVE-2023-39472

Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote a…

Fix: 8.1.32+
Fix from $1,600 2024-05-03
Unclassified HIGH 7.1
CVE-2024-29010

The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure …

Mitigation only
Fix from $1,950 2024-05-01
Websphere Application Server HIGH 7.0
CVE-2024-22354

IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External En…

Fix: 8.5.5.26 / 9.0.5.20+
Fix from $1,950 2024-04-17
Bi Publisher CRITICAL 9.8
CVE-2024-21082

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 a…

Mitigation only
Fix from $2,300 2024-04-16
Unclassified MEDIUM 6.3
CVE-2023-49234

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files an…

Mitigation only
Fix from $1,600 2024-03-29
Powerprotect Data Manager MEDIUM 6.5
CVE-2024-25971

Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could poten…

Fix: 19.16+
Fix from $1,600 2024-03-28
Teamcity HIGH 8.1
CVE-2024-31139

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

Fix: 2024.03+
Fix from $1,950 2024-03-28
Easyadmin HIGH 8.8
CVE-2024-2826

A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /urepo…

Fix: after 2024-03-15
Fix from $1,950 2024-03-22
Unclassified MEDIUM 5.8
CVE-2024-28039

Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker …

Mitigation only
Fix from $1,600 2024-03-18
Maximo Application Suite HIGH 8.2
CVE-2024-27266

IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could…

Patch available
Fix from $1,950 2024-03-14
Pega Platform HIGH 7.7
CVE-2023-50168

Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.

Fix: 8.8.5+
Fix from $1,950 2024-03-14
Openolat HIGH 7.5
CVE-2024-28198

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests…

Fix: 18.1.6+
Fix from $1,950 2024-03-11
Security Guardium Key Lifecycle Manager HIGH 8.2
CVE-2023-25926

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when proce…

Fix: 4.1.1.7+
Fix from $1,950 2024-02-29
Ambari MEDIUM 6.5
CVE-2023-50380

XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De…

Fix: 2.7.8+
Fix from $1,600 2024-02-27
Codeql Cli MEDIUM 5.5
CVE-2024-25129

The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read…

Fix: 2.16.3+
Fix from $1,600 2024-02-22
Digital Experience Platform HIGH 8.7
CVE-2024-25606

XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12,…

Fix: 7.2 / 7.4.3.8+
Fix from $1,950 2024-02-20
Connect Secure HIGH 8.3
CVE-2024-22024EPSS 95%

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate…

Mitigation only
Fix from $1,950 2024-02-13
Netweaver Application Server Java HIGH 7.5
CVE-2024-24743

SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f…

Mitigation only
Fix from $1,950 2024-02-13
Magic Xpi Integration Platform MEDIUM 6.5
CVE-2023-52239

The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

No fix yet
Fix from $1,600 2024-02-06
Security Verify Access HIGH 7.1
CVE-2023-32327

IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 …

Fix: after 10.0.6.1
Fix from $1,950 2024-02-03
Movitools Motionstudio HIGH 7.5
CVE-2024-1167

When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

Mitigation only
Fix from $1,950 2024-02-01