Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Teamcenter HIGH 7.5
CVE-2022-29801

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application con…

Fix: 12.4.0.13 / 13.0.0.9+
Fix from $1,950 2022-05-20
Storable Configs HIGH 8.8
CVE-2022-30971

Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.0
Fix from $1,950 2022-05-17
Unica HIGH 7.5
CVE-2021-27777

XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validatio…

Fix: 12.1.1+
Fix from $1,950 2022-05-12
Api Manager CRITICAL 9.1
CVE-2021-42646

XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.…

Patch available
Fix from $2,300 2022-05-11
Managed File Transfer Command Center CRITICAL 9.1
CVE-2022-22774

The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Com…

Fix: 8.3.2 / 8.4.2+
Fix from $2,300 2022-05-10
Twelvemonkeys CRITICAL 9.8
CVE-2021-23792

The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initia…

Fix: 3.7.1+
Fix from $2,300 2022-05-06
Jena CRITICAL 9.8
CVE-2022-28890

A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers…

Mitigation only
Fix from $2,300 2022-05-05
Administration Center MEDIUM 6.5
CVE-2022-29943

Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access…

Mitigation only
Fix from $1,600 2022-05-04
Enterprise Nfv Infrastructure Software HIGH 7.4
CVE-2022-20780EPSS 11%

Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM…

Fix: 4.7.1+
Fix from $1,950 2022-05-04
Dmars MEDIUM 5.5
CVE-2022-1331

In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific p…

Fix: 2.1.10.24+
Fix from $1,600 2022-05-03
Open Build Service HIGH 8.8
CVE-2022-21949

A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entiti…

Fix: 2.10.13+
Fix from $1,950 2022-05-03
Nifi HIGH 7.5
CVE-2022-29265

Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content …

Fix: after 1.16.0
Fix from $1,950 2022-04-30
Solar Appscreener CRITICAL 9.8
CVE-2022-24449

Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document.

Fix: after 3.10.4
Fix from $2,300 2022-04-28
Detekt CRITICAL 9.8
CVE-2022-0272

Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.

Fix: 1.20.0+
Fix from $2,300 2022-04-21
Roboguide MEDIUM 5.3
CVE-2021-43990

The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an exter…

Fix: after 9.40083.00.05
Fix from $1,600 2022-04-20
Scadapack Workbench MEDIUM 5.5
CVE-2022-0221

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a mali…

Fix: after 6.6.8a
Fix from $1,600 2022-04-13
Manageengine Adaudit Plus CRITICAL 9.8
CVE-2022-28219EPSS 97%

Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

Fix: after 6.0
Fix from $2,300 2022-04-05
Connected Components Workbench MEDIUM 5.5
CVE-2022-1018

When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe ca…

Fix: after 12.0
Fix from $1,600 2022-04-01
Mashzone Nextgen HIGH 7.2
CVE-2021-33208

The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration f…

Fix: after 10.7
Fix from $1,950 2022-03-30
Jox CRITICAL 9.8
CVE-2021-43142

An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput.

Fix: after 1.16
Fix from $2,300 2022-03-30
Coverage\/complexity Scatter Plot HIGH 8.1
CVE-2022-28154

Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.1.1
Fix from $1,950 2022-03-29
Pipeline\ HIGH 8.1
CVE-2022-28155

Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.3
Fix from $1,950 2022-03-29
Flaky Test Handler HIGH 8.1
CVE-2022-28140

Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.2.1
Fix from $1,950 2022-03-29
Toolboxst HIGH 7.5
CVE-2021-44477

GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that cou…

Fix: 07.09.07c+
Fix from $1,950 2022-03-25
Soa Model CRITICAL 9.8
CVE-2021-43090

An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function.

Fix: 1.6.4+
Fix from $2,300 2022-03-25
Eyoucms HIGH 7.2
CVE-2021-42194

The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String func…

No fix yet
Fix from $1,950 2022-03-20
Cvrf Csaf Converter MEDIUM 5.5
CVE-2022-27193

CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the gen…

Mitigation only
Fix from $1,600 2022-03-15
Debian Linux MEDIUM 6.5
CVE-2022-26661

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tr…

Fix: 5.0.12 / 5.0.46+
Fix from $1,600 2022-03-10
Geocall MEDIUM 6.5
CVE-2022-22835EPSS 15%

An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exp…

Fix: 8.0+
Fix from $1,600 2022-03-10
Manager\+agents CRITICAL 9.1
CVE-2022-22795

Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the p…

Fix: 13.5+
Fix from $2,300 2022-03-10