Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Tsclinical Define.xml Generator HIGH 7.4
CVE-2023-22377

Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) a…

Fix: 1.1.1+
Fix from $1,950 2023-02-15
Ureport HIGH 7.8
CVE-2023-24187

An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/…

No fix yet
Fix from $1,950 2023-02-14
Nifi HIGH 7.5
CVE-2023-22832

The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i…

Fix: after 1.19.1
Fix from $1,950 2023-02-10
Mojoportal HIGH 8.8
CVE-2023-24323

Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.

No fix yet
Fix from $1,950 2023-02-09
Remote Engine Gen 2 HIGH 7.8
CVE-2022-45588

All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should do…

Mitigation only
Fix from $1,950 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-38389

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Tivoli Workload Scheduler CRITICAL 9.1
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $2,300 2023-02-03
Keos CRITICAL 9.8
CVE-2022-47873

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

Mitigation only
Fix from $2,300 2023-01-31
Cx Motion Pro MEDIUM 5.5
CVE-2023-22322

Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a spec…

Fix: 1.4.6.014+
Fix from $1,600 2023-01-30
Testcomplete Support CRITICAL 9.8
CVE-2023-24443

Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.8.1
Fix from $2,300 2023-01-26
Semantic Versioning CRITICAL 9.8
CVE-2023-24429

Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio…

Fix: 1.15+
Fix from $2,300 2023-01-26
Semantic Versioning CRITICAL 9.8
CVE-2023-24430

Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.15+
Fix from $2,300 2023-01-26
Mstest CRITICAL 9.8
CVE-2023-24441

Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0.0
Fix from $2,300 2023-01-26
Web Services Manager HIGH 8.1
CVE-2023-21862

Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component). The supported version tha…

Patch available
Fix from $1,950 2023-01-18
Manageengine Exchange Reporter Plus HIGH 7.5
CVE-2023-22624

Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.

Fix: 5.7+
Fix from $1,950 2023-01-17
Device Registration Portal HIGH 7.5
CVE-2023-23595

BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "m…

No fix yet
Fix from $1,950 2023-01-15
Open Studio CRITICAL 9.8
CVE-2021-4311

A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handl…

Fix: 20230102_1935+
Fix from $2,300 2023-01-09
Simplexrd CRITICAL 9.8
CVE-2015-10029

A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/…

Fix: 3.1.1+
Fix from $2,300 2023-01-07
Dssp CRITICAL 9.8
CVE-2016-15011

A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse …

Fix: 1.3.2+
Fix from $2,300 2023-01-06
Axmlrpc CRITICAL 9.8
CVE-2020-36641

A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the fil…

Fix: after 1.12.1
Fix from $2,300 2023-01-05
Webservice Connector CRITICAL 9.8
CVE-2020-36640

A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function Tran…

Fix: 1.3.1+
Fix from $2,300 2023-01-05
Rups CRITICAL 9.8
CVE-2017-20151

A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rup…

Fix: 2017-08-01+
Fix from $2,300 2022-12-30
Code Validator Api CRITICAL 9.8
CVE-2021-4295

A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidat…

Fix: 1.0.31+
Fix from $2,300 2022-12-29
Dragonfly HIGH 7.5
CVE-2022-41967

Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML externa…

Patch available
Fix from $1,950 2022-12-28
Ogc Web Feature Service CRITICAL 9.8
CVE-2022-4607

A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown …

Fix: 5.2.1+
Fix from $2,300 2022-12-18
Xml Rpc.net HIGH 8.8
CVE-2022-47514

An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request for…

Fix: 2.5.0+
Fix from $1,950 2022-12-18
Symantec Identity Governance And Administration HIGH 8.8
CVE-2022-25628

An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4

Mitigation only
Fix from $1,950 2022-12-16
Sd Wan MEDIUM 5.5
CVE-2022-37911

Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allo…

Fix: 6.5.4.22 / 8.6.0.17+
Fix from $1,600 2022-12-12
Plot CRITICAL 9.8
CVE-2022-46682

Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 2.1.12+
Fix from $2,300 2022-12-12
Intellij Idea MEDIUM 5.5
CVE-2022-46827

In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.

Fix: 2022.3+
Fix from $1,600 2022-12-08