Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Py Xml HIGH 7.5
CVE-2020-26709

py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a cra…

Mitigation only
Fix from $1,950 2023-06-29
Easy Parse HIGH 7.5
CVE-2020-26710

easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via …

Mitigation only
Fix from $1,950 2023-06-29
Xclarity Administrator HIGH 7.5
CVE-2023-3113

An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read…

Fix: 4.0.0+
Fix from $1,950 2023-06-26
Hutool HIGH 7.5
CVE-2023-3276

A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax…

Fix: after 5.8.19
Fix from $1,950 2023-06-15
Arcsight Logger CRITICAL 9.1
CVE-2023-24470

Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.

Fix: 7.3.0+
Fix from $2,300 2023-06-13
Frenic Rhc Loader MEDIUM 5.5
CVE-2023-29498

Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a special…

Fix: after 1.1.0.3
Fix from $1,600 2023-06-13
Xml Library HIGH 7.5
CVE-2023-34411

The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an X…

Fix: 0.8.14+
Fix from $1,950 2023-06-05
Splunk MEDIUM 6.5
CVE-2023-32706

On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with…

Fix: 8.1.14 / 8.2.11+
Fix from $1,600 2023-06-01
Archive Center Administration HIGH 7.1
CVE-2022-41221

The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administrati…

Fix: after 21.2
Fix from $1,950 2023-05-24
E Cology HIGH 8.8
CVE-2023-2806

A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of …

No fix yet
Fix from $1,950 2023-05-19
Opc Factory Server MEDIUM 5.5
CVE-2023-2161

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system wh…

Fix: 3.63+
Fix from $1,600 2023-05-16
Websphere Application Server MEDIUM 6.3
CVE-2023-27554

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Fix: 8.5.5.24 / 9.0.5.16+
Fix from $1,600 2023-05-11
Shinseiyo Sogo Soft HIGH 7.5
CVE-2023-27527

Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitra…

Fix: after 7.9a
Fix from $1,950 2023-05-10
Vbase MEDIUM 5.5
CVE-2022-45876

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-04-26
Workload Automation HIGH 8.1
CVE-2023-28008

HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2023-04-26
Workload Automation HIGH 8.1
CVE-2023-28009

HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…

Mitigation only
Fix from $1,950 2023-04-26
Netact MEDIUM 6.5
CVE-2023-26057

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper X…

Mitigation only
Fix from $1,600 2023-04-25
Netact MEDIUM 6.5
CVE-2023-26058

An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML par…

Mitigation only
Fix from $1,600 2023-04-25
Super Clean MEDIUM 5.5
CVE-2023-27652

An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field…

No fix yet
Fix from $1,600 2023-04-20
Man Eam 0003 HIGH 7.5
CVE-2022-38840EPSS 10%

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file…

No fix yet
Fix from $1,950 2023-04-16
Data Catalog MEDIUM 5.5
CVE-2023-26263

All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/licen…

Fix: 8.0-20230110+
Fix from $1,600 2023-04-13
Data Catalog MEDIUM 5.5
CVE-2023-26264

All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.

Fix: 8.0-20220907+
Fix from $1,600 2023-04-13
Polarion Alm MEDIUM 5.9
CVE-2023-28828

A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerabil…

Fix: 2304.0+
Fix from $1,600 2023-04-11
National Land Numerical Information Data Conversion Tool MEDIUM 5.5
CVE-2023-25955

National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a spec…

Mitigation only
Fix from $1,600 2023-04-11
Manageengine Applications Manager MEDIUM 6.5
CVE-2023-28340

Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.

Fix: 16.3+
Fix from $1,600 2023-04-11
Tririga Application Platform HIGH 7.1
CVE-2023-27876

IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera…

Patch available
Fix from $1,950 2023-04-07
Identity Services Engine MEDIUM 6.0
CVE-2023-20030

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access…

Fix: 3.2+
Fix from $1,600 2023-04-05
Vantara Pentaho Business Analytics Server MEDIUM 6.5
CVE-2022-43941

Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis ser…

Fix: 9.3.0.2+
Fix from $1,600 2023-04-03
Crap4j HIGH 7.5
CVE-2023-28680

Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.9
Fix from $1,950 2023-04-02
Visual Studio Code Metrics HIGH 8.2
CVE-2023-28681

Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.7
Fix from $1,950 2023-04-02