Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Prosody HIGH 7.5
CVE-2022-0217

It was discovered that an internal Prosody library to load XML based on libexpat does not properly restrict the XML features allowed in parsed XML da…

Fix: 0.11.12+
Fix from $1,950 2022-08-26
Mq CRITICAL 9.1
CVE-2022-22489

IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A rem…

Patch available
Fix from $2,300 2022-08-19
Jboss A Mq MEDIUM 5.6
CVE-2020-14379

A flaw was found in Red Hat AMQ Broker in a way that a XEE attack can be done via Broker's configuration files, leading to denial of service and info…

Mitigation only
Fix from $1,600 2022-08-16
Sphinx MEDIUM 5.3
CVE-2022-2838

In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the…

Fix: 0.13.1+
Fix from $1,600 2022-08-16
Manageengine Analytics Plus HIGH 7.5
CVE-2020-21641

Out-of-Band XML External Entity (OOB-XXE) vulnerability in Zoho ManageEngine Analytics Plus before 4.3.5 allows remote attackers to read arbitrary fi…

Fix: 4.3.5+
Fix from $1,950 2022-08-15
Process Automation Manager HIGH 8.2
CVE-2022-2458

XML external entity injection(XXE) is a vulnerability that allows an attacker to interfere with an application's processing of XML data. This attack …

Fix: 7.13.1+
Fix from $1,950 2022-08-10
Ignition CRITICAL 9.8
CVE-2022-1704

Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a …

Fix: 7.9.21 / 8.1.8+
Fix from $2,300 2022-08-05
Datapower Gateway CRITICAL 9.1
CVE-2022-31775

IBM DataPower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.8, 10.5.0.0, and 2018.4.1.0 through 2018.4.1.21 is vulnerable to an XML Exte…

Fix: 10.0.1.8 / 10.5.0.1+
Fix from $2,300 2022-08-01
Dogtagpki HIGH 7.5
CVE-2022-2414EPSS 86%

Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks. This flaw allows a remote attacker to potential…

Patch available
Fix from $1,950 2022-07-29
Fusion 360 HIGH 7.8
CVE-2022-27873

An attacker can force the victim’s device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360’…

Fix: after 2.0.12887
Fix from $1,950 2022-07-29
Vbase Web Remote HIGH 7.5
CVE-2021-42537

VISAM VBASE version 11.6.0.6 processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphe…

Mitigation only
Fix from $1,950 2022-07-27
Untangle HIGH 7.5
CVE-2022-31471

untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity refe…

Fix: after 1.2.0
Fix from $1,950 2022-07-26
Openkm CRITICAL 9.8
CVE-2022-2131

OpenKM Community Edition in its 6.3.10 version and before was using XMLReader parser in XMLTextExtractor.java file without the required security flag…

Fix: after 6.3.10
Fix from $2,300 2022-07-25
Business Process Management HIGH 7.5
CVE-2022-32458

Digiwin BPM has a XML External Entity Injection (XXE) vulnerability due to insufficient validation for user input. An unauthenticated remote attacker…

Fix: 5.8.8.1+
Fix from $1,950 2022-07-20
Partner Engagement Manager HIGH 7.1
CVE-2022-22358

IBM Sterling Partner Engagement Manager 6.1.2, 6.2, and Cloud/SasS 22.2 is vulnerable to an XML External Entity Injection (XXE) attack when processin…

Fix: 6.1.2.5 / 6.2.0.3+
Fix from $1,950 2022-07-19
Enterprise Resource Planning MEDIUM 6.5
CVE-2022-34001

Unit4 ERP through 7.9 allows XXE via ExecuteServerProcessAsynchronously.

Fix: after 7.9
Fix from $1,600 2022-07-19
Hudson CRITICAL 9.8
CVE-2015-8031

Hudson (aka org.jvnet.hudson.main:hudson-core) before 3.3.2 allows XXE attacks.

Fix: 3.2.2+
Fix from $2,300 2022-07-18
Cloudstack CRITICAL 9.8
CVE-2022-35741EPSS 8%

Apache CloudStack version 4.5.0 and later has a SAML 2.0 authentication Service Provider plugin which is found to be vulnerable to XML external entit…

Fix: 4.16.1.1+
Fix from $2,300 2022-07-18
Business One HIGH 7.5
CVE-2022-35168

Due to improper input sanitization of XML input in SAP Business One - version 10.0, an attacker can perform a denial-of-service attack rendering the …

Mitigation only
Fix from $1,950 2022-07-12
Lyo MEDIUM 5.3
CVE-2021-41042

In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/…

Fix: after 4.1.0
Fix from $1,600 2022-07-07
Recipe HIGH 8.8
CVE-2022-34793

Jenkins Recipe Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.2
Fix from $1,950 2022-06-30
Okta Sso CRITICAL 9.8
CVE-2022-23170

SysAid - Okta SSO integration - was found vulnerable to XML External Entity Injection vulnerability. Any SysAid environment that uses the Okta SSO in…

Fix: after 22.1.63
Fix from $2,300 2022-06-24
Mastro HIGH 7.5
CVE-2021-40510

XML eXternal Entity (XXE) in OBDA systems’ Mastro 1.0 allows remote attackers to read system files via custom DTDs.

Mitigation only
Fix from $1,950 2022-06-21
Ags Zena CRITICAL 9.8
CVE-2021-45024

ASG technologies ( A Rocket Software Company) ASG-Zena Cross Platform Server Enterprise Edition 4.2.1 is vulnerable to XML External Entity (XXE).

Mitigation only
Fix from $2,300 2022-06-17
Drools CRITICAL 9.8
CVE-2021-41411

drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, res…

Fix: 7.6.0+
Fix from $2,300 2022-06-16
Saml HIGH 7.5
CVE-2022-32285

A vulnerability has been identified in Mendix SAML Module (Mendix 7 compatible) (All versions < V1.16.6), Mendix SAML Module (Mendix 8 compatible) (A…

Fix: 1.16.6 / 2.2.2+
Fix from $1,950 2022-06-14
Magicpin HIGH 7.5
CVE-2022-31447

An XML external entity (XXE) injection vulnerability in Magicpin v3.4 allows attackers to access sensitive database information via a crafted SVG fil…

No fix yet
Fix from $1,950 2022-06-14
Ngeniusone CRITICAL 9.8
CVE-2021-45981

NetScout nGeniusONE 6.3.2 allows an XML External Entity (XXE) attack.

Mitigation only
Fix from $2,300 2022-06-02
Tools HIGH 7.1
CVE-2022-22977

VMware Tools for Windows(12.0.0, 11.x.y and 10.x.y) contains an XML External Entity (XXE) vulnerability. A malicious actor with non-administrative lo…

Fix: 12.0.5+
Fix from $1,950 2022-05-24
Morpheus HIGH 7.5
CVE-2022-31261

An XXE issue was discovered in Morpheus through 5.2.16 and 5.4.x through 5.4.4. A successful attack requires a SAML identity provider to be configure…

Fix: after 5.4.4
Fix from $1,950 2022-05-24