Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Performance Publisher HIGH 8.2
CVE-2023-28682

Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 8.09
Fix from $1,950 2023-04-02
Phabricator Differential HIGH 8.2
CVE-2023-28683

Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.1.5
Fix from $1,950 2023-04-02
Remote Jobs View MEDIUM 6.5
CVE-2023-28684

Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.0.3
Fix from $1,600 2023-04-02
Manageengine Opmanager MEDIUM 5.4
CVE-2022-43473EPSS 20%

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM…

Fix: 12.6+
Fix from $1,600 2023-03-30
Aveva Edge HIGH 7.1
CVE-2022-36969EPSS 14%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.…

Fix: 2020.2.00.40+
Fix from $1,950 2023-03-29
Jodf CRITICAL 9.8
CVE-2023-28150

An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX fi…

Fix: 1.1.110+
Fix from $2,300 2023-03-24
Jspreadsheet CRITICAL 9.8
CVE-2023-28151

An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a…

Fix: 1.1.110+
Fix from $2,300 2023-03-24
Jword CRITICAL 9.8
CVE-2023-28152

An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX f…

Fix: 1.1.110+
Fix from $2,300 2023-03-24
Absint A3 HIGH 7.1
CVE-2023-28685

Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.0
Fix from $1,950 2023-03-22
Vbase Automation Base MEDIUM 5.5
CVE-2022-41696

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-03-21
Vbase Automation Base MEDIUM 5.5
CVE-2022-43512

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-03-21
Vbase Automation Base MEDIUM 5.5
CVE-2022-45121

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-03-21
Vbase Automation Base MEDIUM 5.5
CVE-2022-45468

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-03-21
Vbase Automation Base MEDIUM 5.5
CVE-2022-46300

Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.

Fix: 11.7.5+
Fix from $1,600 2023-03-21
Wechat Sdk Python CRITICAL 9.8
CVE-2018-25082

A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipula…

Fix: 0.5.5+
Fix from $2,300 2023-03-21
Aspera Faspex HIGH 8.8
CVE-2023-27874

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul…

Fix: after 4.4.2
Fix from $1,950 2023-03-21
Enovia Live Collaboration HIGH 7.5
CVE-2023-1288

An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.

Mitigation only
Fix from $1,950 2023-03-09
Owslib HIGH 7.5
CVE-2023-27476

OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content mo…

Fix: 0.28.1+
Fix from $1,950 2023-03-08
Xwiki HIGH 7.7
CVE-2023-27480

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…

Fix: 13.10.11 / 14.4.7+
Fix from $1,950 2023-03-07
Secure Endpoint MEDIUM 5.3
CVE-2023-20052EPSS 7%

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV vers…

Fix: 1.20.2 / 1.21.1+
Fix from $1,600 2023-03-01
Geonode MEDIUM 6.5
CVE-2023-26043

GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML …

Fix: 4.0.3+
Fix from $1,600 2023-02-27
Urule CRITICAL 9.8
CVE-2023-24189

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/comm…

No fix yet
Fix from $2,300 2023-02-24
Vrealize Automation HIGH 8.8
CVE-2023-20855

VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche…

Fix: 8.11.1+
Fix from $1,950 2023-02-22
Php Saml Sp MEDIUM 6.5
CVE-2023-26267

php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silent…

Fix: 1.1.1 / 2.1.1+
Fix from $1,600 2023-02-21
Libplist CRITICAL 9.8
CVE-2015-10082

A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c o…

Patch available
Fix from $2,300 2023-02-21
Dd Plist HIGH 7.8
CVE-2016-15026

A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulat…

Fix: 1.18+
Fix from $1,950 2023-02-20
Java Xmlbuilder CRITICAL 9.8
CVE-2014-125087

A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The m…

Fix: 1.2+
Fix from $2,300 2023-02-19
Openkm HIGH 7.5
CVE-2021-33950

An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.

Patch available
Fix from $1,950 2023-02-17
Fortinac CRITICAL 9.1
CVE-2022-39954

An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, Fort…

Fix: 7.2.0 / 9.4.2+
Fix from $2,300 2023-02-16
Awesome Procedures On Cyper HIGH 8.1
CVE-2023-23926

APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml proce…

Fix: 5.5.0+
Fix from $1,950 2023-02-16