Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Appbuilder MEDIUM 6.5
CVE-2023-4554

Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Prob…

Fix: 23.2+
Fix from $1,600 2024-01-29
Electronic Delivery Check System MEDIUM 5.5
CVE-2024-21765

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delive…

Fix: 11.0.0 / 13.0.0+
Fix from $1,600 2024-01-24
Electronic Deliverables Creation Support Tool MEDIUM 5.5
CVE-2024-21796

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Su…

Fix: 1.0.4+
Fix from $1,600 2024-01-24
Electronic Delivery Check System MEDIUM 5.5
CVE-2024-22380

Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heise…

Fix: after 14.0.001.002
Fix from $1,600 2024-01-24
Spreadsheet\ MEDIUM 6.5
CVE-2024-23525

The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig.

Fix: 0.30+
Fix from $1,600 2024-01-18
Fonttools HIGH 7.5
CVE-2023-45139

fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which…

Fix: 4.43.0+
Fix from $1,950 2024-01-10
Web Application Screening MEDIUM 6.5
CVE-2023-6149

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission …

Fix: after 2.0.11
Fix from $1,600 2024-01-09
Policy Compliance MEDIUM 6.5
CVE-2023-6147

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing …

Fix: after 1.0.5
Fix from $1,600 2024-01-09
Ngeniusone CRITICAL 9.8
CVE-2023-26999

An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file.

Mitigation only
Fix from $2,300 2024-01-09
Unified Remote CRITICAL 9.8
CVE-2023-52252

Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload…

No fix yet
Fix from $2,300 2023-12-30
Avalanche CRITICAL 9.8
CVE-2023-46265

An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).

Fix: after 6.4.1
Fix from $2,300 2023-12-19
Wps HIGH 7.5
CVE-2023-6280

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the …

Fix: 4.0.0+
Fix from $1,950 2023-12-19
Api Manager HIGH 7.5
CVE-2023-6836

Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used featur…

Fix: after 6.6.0
Fix from $1,950 2023-12-15
Repox HIGH 7.5
CVE-2023-6721

An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileuploa…

Mitigation only
Fix from $1,950 2023-12-13
Memory Analyzer HIGH 7.1
CVE-2023-6194

In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references…

Fix: after 1.14.0
Fix from $1,950 2023-12-11
Cocoon CRITICAL 9.8
CVE-2023-49733

Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User…

Fix: 2.3.0+
Fix from $2,300 2023-11-30
Matlab CRITICAL 9.8
CVE-2023-49656

Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 2.11.1+
Fix from $2,300 2023-11-29
Robohelp Server HIGH 7.5
CVE-2023-22274

Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c…

Fix: after 11.4
Fix from $1,950 2023-11-17
Siemens Opc Ua Modeling Editor HIGH 7.5
CVE-2023-46590

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external en…

Fix: 2.8+
Fix from $1,950 2023-11-14
Eclipse Ide MEDIUM 5.0
CVE-2023-4218

In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to o…

Fix: 3.13.2400 / 3.29.0+
Fix from $1,600 2023-11-09
Topografix Data Plugin MEDIUM 5.5
CVE-2023-5136

An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulne…

Mitigation only
Fix from $1,600 2023-11-08
E Tax MEDIUM 5.5
CVE-2023-46802

e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parse…

Fix: after 3.0.10
Fix from $1,600 2023-11-06
Opencrx CRITICAL 9.8
CVE-2023-46502

An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuild…

Patch available
Fix from $2,300 2023-10-30
Agile Reporter MEDIUM 6.5
CVE-2022-34832

An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component.

No fix yet
Fix from $1,600 2023-10-27
Unity Operating Environment MEDIUM 6.5
CVE-2023-43067

Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosin…

Fix: 5.3.0.0.5.120+
Fix from $1,600 2023-10-23
Cx Designer MEDIUM 5.5
CVE-2023-43624

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vuln…

Fix: after 3.740
Fix from $1,600 2023-10-23
Proself HIGH 7.5
CVE-2023-45727 KEV

Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and e…

Fix: 1.09 / 1.66+
Fix from $1,950 2023-10-18
Security Directory Server CRITICAL 9.1
CVE-2022-32755

IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could …

Patch available
Fix from $2,300 2023-10-14
Azure Hdinsight CRITICAL 9.8
CVE-2023-36419

Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability

Patch available
Fix from $2,300 2023-10-10
Ktor CRITICAL 9.8
CVE-2023-45612

In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE

Fix: 2.3.5+
Fix from $2,300 2023-10-09