Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Mobile CRITICAL 9.8
CVE-2022-3980EPSS 8%

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premise…

Fix: 9.7.5+
Fix from $2,300 2022-11-16
Osf Builder Suite \ CRITICAL 9.8
CVE-2022-45397

Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0.2
Fix from $2,300 2022-11-15
Japex CRITICAL 9.8
CVE-2022-45400

Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.7
Fix from $2,300 2022-11-15
Cccc CRITICAL 9.8
CVE-2022-45395

Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.6
Fix from $2,300 2022-11-15
Sourcemonitor CRITICAL 9.8
CVE-2022-45396

Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.2
Fix from $2,300 2022-11-15
Violations MEDIUM 5.5
CVE-2022-45386

Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.7.11
Fix from $1,600 2022-11-15
Concrete Cms MEDIUM 5.3
CVE-2022-43689

Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.

Fix: 8.5.10+
Fix from $1,600 2022-11-14
Splunk MEDIUM 6.5
CVE-2022-43570

In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (…

Fix: 8.1.12 / 8.2.9+
Fix from $1,600 2022-11-04
Intrusion Prevention System Manager HIGH 7.2
CVE-2022-3340

XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in …

Fix: 10.1+
Fix from $1,950 2022-11-04
Candidats HIGH 7.5
CVE-2022-42745

CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable t…

No fix yet
Fix from $1,950 2022-11-03
Infosphere Information Server CRITICAL 9.1
CVE-2022-40747

"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Patch available
Fix from $2,300 2022-11-03
Cloud Foundation CRITICAL 9.1
CVE-2022-31678EPSS 8%

VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user …

Fix: 3.11 / 6.4.14+
Fix from $2,300 2022-10-28
Compuware Topaz For Total Test HIGH 7.5
CVE-2022-43430

Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.4.8
Fix from $1,950 2022-10-19
Repo HIGH 7.5
CVE-2022-43415

Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.16.0+
Fix from $1,950 2022-10-19
Epolicy Orchestrator MEDIUM 5.4
CVE-2022-3338

An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Ser…

Fix: 5.10.0+
Fix from $1,600 2022-10-18
Coldfusion HIGH 7.5
CVE-2022-42341EPSS 36%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference…

Mitigation only
Fix from $1,950 2022-10-14
Coldfusion HIGH 7.5
CVE-2022-38419EPSS 53%

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by an Improper Restriction of XML External Entity Reference…

Patch available
Fix from $1,950 2022-10-14
Netbackup CRITICAL 9.8
CVE-2022-42307

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML Exte…

Fix: after 10.0.0.1
Fix from $2,300 2022-10-03
Netbackup HIGH 8.8
CVE-2022-42301

An issue was discovered in Veritas NetBackup through 10.0.0.1 and related Veritas products. The NetBackup Primary server is vulnerable to an XML Exte…

Fix: after 10.0.0.1
Fix from $1,950 2022-10-03
Sterling Partner Engagement Manager HIGH 7.1
CVE-2022-34348

IBM Sterling Partner Engagement Manager 6.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Fix: 6.1.2.6 / 6.2.0.4+
Fix from $1,950 2022-09-23
Soap HIGH 7.5
CVE-2022-40705

An Improper Restriction of XML External Entity Reference vulnerability in RPCRouterServlet of Apache SOAP allows an attacker to read arbitrary files …

Mitigation only
Fix from $1,950 2022-09-22
Rqm CRITICAL 9.1
CVE-2022-41241

Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.8
Fix from $2,300 2022-09-21
Compuware Common Configuration CRITICAL 9.8
CVE-2022-41226

Jenkins Compuware Common Configuration Plugin 1.0.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: 1.0.15+
Fix from $2,300 2022-09-21
Fme Server MEDIUM 6.5
CVE-2022-38342

Safe Software FME Server v2021.2.5, v2022.0.0.2 and below was discovered to contain a XML External Entity (XXE) vulnerability which allows authentica…

Fix: 2021.2.6.0 / 2022.0.0.2+
Fix from $1,600 2022-09-13
Cloud Security Gateway CRITICAL 9.8
CVE-2022-1700

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is a…

Fix: 8.5.5 / 8.8.2+
Fix from $2,300 2022-09-12
Calcite CRITICAL 9.8
CVE-2022-39135

Apache Calcite 1.22.0 introduced the SQL operators EXISTS_NODE, EXTRACT_XML, XML_TRANSFORM and EXTRACT_VALUE do not restrict XML External Entity refe…

Fix: 1.32.0+
Fix from $2,300 2022-09-11
Mei2volpiano HIGH 7.5
CVE-2022-37189

DDMAL MEI2Volpiano 0.8.2 is vulnerable to XML External Entity (XXE), leading to a Denial of Service. This occurs due to the usage of the unsafe 'xml.…

Fix: after 0.8.2
Fix from $1,950 2022-09-07
Cognos Analytics HIGH 8.1
CVE-2022-36773

IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…

Fix: 11.1.7 / 11.2.3+
Fix from $1,950 2022-09-01
Delta Robot Automation Studio HIGH 8.6
CVE-2022-2759

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes a…

Fix: 1.13.20+
Fix from $1,950 2022-08-31
Data Loss Prevention Endpoint MEDIUM 6.5
CVE-2022-2330

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause t…

Fix: 11.6.600.212 / 11.9.100+
Fix from $1,600 2022-08-30