Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Gradle MEDIUM 5.3
CVE-2023-42445

Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso…

Fix: 7.6.3 / 8.4.0+
Fix from $1,600 2023-10-06
Fd Application MEDIUM 5.5
CVE-2023-42132

FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially craf…

Fix: after 9.01
Fix from $1,600 2023-10-02
Endpoint Manager HIGH 7.5
CVE-2023-38343

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity referen…

Fix: 2022+
Fix from $1,950 2023-09-21
Assistant HIGH 7.4
CVE-2023-3892

Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking …

Mitigation only
Fix from $1,950 2023-09-19
Job Configuration History HIGH 8.8
CVE-2023-41933

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attac…

Fix: after 1229.v3039470161a_d
Fix from $1,950 2023-09-06
Job Configuration History MEDIUM 6.5
CVE-2023-41932

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowi…

Fix: after 1227.v7a_79fc4dc01f
Fix from $1,600 2023-09-06
Financial Transaction Manager CRITICAL 9.1
CVE-2023-35892

IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2023-09-05
C2132 Firmware HIGH 7.5
CVE-2023-40239

Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.…

Mitigation only
Fix from $1,950 2023-09-01
Leshan CRITICAL 9.8
CVE-2023-41034

Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and s…

Fix: 1.5.0+
Fix from $2,300 2023-08-31
Yamlbeans MEDIUM 5.5
CVE-2023-24620

An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans …

Fix: after 1.15
Fix from $1,600 2023-08-25
Python CRITICAL 9.8
CVE-2022-48565

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist fil…

Fix: 3.6.13 / 3.7.10+
Fix from $2,300 2023-08-22
Ivy HIGH 8.2
CVE-2022-46751

Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I…

Fix: 2.5.2+
Fix from $1,950 2023-08-21
Horizon MEDIUM 6.1
CVE-2023-0871

XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external e…

Fix: 32.0.2 / 2020.1.38+
Fix from $1,600 2023-08-11
PHP HIGH 7.5
CVE-2023-3823

In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configura…

Fix: 8.0.30 / 8.1.22+
Fix from $1,950 2023-08-11
Avalanche CRITICAL 9.8
CVE-2023-32567

Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Dynamics 365 MEDIUM 6.5
CVE-2023-35389

Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability

Fix: 9.0.47.08 / 9.1.18.22+
Fix from $1,600 2023-08-08
Catalyst Sd Wan Manager HIGH 8.1
CVE-2020-26064

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to informa…

Mitigation only
Fix from $1,950 2023-08-04
Unica HIGH 8.8
CVE-2023-37497

The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights …

Fix: 11.1.0.6 / 12.1.1+
Fix from $1,950 2023-08-03
Magritte Rest Source Bundle MEDIUM 6.5
CVE-2023-30951

The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE).

Fix: 7.210.0+
Fix from $1,600 2023-08-03
J Wbem CRITICAL 9.1
CVE-2023-37364

In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers …

Fix: 4.7.5+
Fix from $2,300 2023-08-03
Kirby CRITICAL 10.0
CVE-2023-38490

Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites tha…

Fix: 3.5.8.3 / 3.6.6.3+
Fix from $2,300 2023-07-27
Applicant Programme MEDIUM 5.5
CVE-2023-32639

Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbit…

Fix: after 7.06
Fix from $1,600 2023-07-25
Xbrl Data Create MEDIUM 5.5
CVE-2023-32635

XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBR…

Fix: after 7.0
Fix from $1,600 2023-07-19
Android CRITICAL 9.8
CVE-2023-20918

In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execut…

Patch available
Fix from $2,300 2023-07-13
External Monitor Job Type MEDIUM 6.5
CVE-2023-37942

Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta…

Fix: after 206.v9a_94ff0b_4a_10
Fix from $1,600 2023-07-12
Ecostruxure Opc Ua Server Expert MEDIUM 5.5
CVE-2023-37200

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a proje…

Fix: 2.01+
Fix from $1,600 2023-07-12
Requests Xml HIGH 7.5
CVE-2020-26708

requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code v…

Mitigation only
Fix from $1,950 2023-06-29
Py Xml HIGH 7.5
CVE-2020-26709

py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a cra…

Mitigation only
Fix from $1,950 2023-06-29
Easy Parse HIGH 7.5
CVE-2020-26710

easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2023-06-29
Xclarity Administrator HIGH 7.5
CVE-2023-3113

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read…

Fix: 4.0.0+
Fix from $1,950 2023-06-26