Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Any23 CRITICAL 9.1
CVE-2022-25312

An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions …

Fix: 2.7+
Fix from $2,300 2022-03-05
Liquibase CRITICAL 9.8
CVE-2022-0839

Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0.

Fix: 4.8.0+
Fix from $2,300 2022-03-04
Hazelcast CRITICAL 9.8
CVE-2022-0265

Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1.

Patch available
Fix from $2,300 2022-03-03
Excel Streaming Reader CRITICAL 9.8
CVE-2022-23640

Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser th…

Fix: 2.1.0+
Fix from $2,300 2022-03-02
Teamcity CRITICAL 9.8
CVE-2022-24340

In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible.

Fix: 2021.2.1+
Fix from $2,300 2022-02-25
Factorytalk Services Platform HIGH 7.1
CVE-2020-14478

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote conten…

Fix: after 6.11.00
Fix from $1,950 2022-02-24
Chef Sinatra HIGH 8.8
CVE-2022-25209

Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.20
Fix from $1,950 2022-02-15
Magnolia Cms HIGH 7.8
CVE-2021-46365

An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

Fix: 6.2.4+
Fix from $1,950 2022-02-11
Quartus Prime HIGH 7.5
CVE-2022-21205

Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an u…

Fix: 21.3+
Fix from $1,950 2022-02-09
Quartus Prime HIGH 7.8
CVE-2022-21220

Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentia…

Fix: 21.3+
Fix from $1,950 2022-02-09
Manager\+agents CRITICAL 9.8
CVE-2021-46660

Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks.

Fix: 15.1+
Fix from $2,300 2022-01-30
Cognos Controller HIGH 8.2
CVE-2020-4875

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Cognos Controller HIGH 8.2
CVE-2020-4876

IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…

Mitigation only
Fix from $1,950 2022-01-21
Jadx MEDIUM 5.5
CVE-2022-0219

Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2.

Fix: 1.3.2+
Fix from $1,600 2022-01-20
Debian Linux MEDIUM 5.3
CVE-2022-21282

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Corenlp CRITICAL 9.8
CVE-2022-0239

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Fix: 4.4.0+
Fix from $2,300 2022-01-17
Experience Manager CRITICAL 9.8
CVE-2021-40722

AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c…

Fix: after 6.5.10.0
Fix from $2,300 2022-01-13
Corenlp HIGH 7.1
CVE-2022-0198

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Fix: after 4.3.2
Fix from $1,950 2022-01-13
Caldera HIGH 8.8
CVE-2021-42560

An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum…

No fix yet
Fix from $1,950 2022-01-12
Kace Desktop Authority MEDIUM 5.5
CVE-2021-44028

XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue …

Fix: 11.2+
Fix from $1,600 2021-12-22
Dbeaver MEDIUM 5.5
CVE-2021-3836

dbeaver is vulnerable to Improper Restriction of XML External Entity Reference

Fix: 21.2.3+
Fix from $1,600 2021-12-14
H2 CRITICAL 9.1
CVE-2021-23463

The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML cl…

Fix: 2.0.202+
Fix from $2,300 2021-12-10
Multiner CRITICAL 9.1
CVE-2021-44557

National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in…

Fix: 08-25-2021+
Fix from $2,300 2021-12-08
Digger CRITICAL 9.1
CVE-2021-44556

National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since…

Fix: 08-25-2021+
Fix from $2,300 2021-12-08
Cloverdx HIGH 7.7
CVE-2021-42776

CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import.

Fix: 5.11.2+
Fix from $1,950 2021-12-01
Filemaker Pro MEDIUM 5.5
CVE-2021-44147

An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files …

Fix: 19.4.1+
Fix from $1,600 2021-11-22
Performance MEDIUM 6.5
CVE-2021-21701

Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 3.20
Fix from $1,600 2021-11-12
Pom2config MEDIUM 6.5
CVE-2021-43576

Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Ove…

Fix: after 1.2
Fix from $1,600 2021-11-12
Owasp Dependency Check HIGH 7.1
CVE-2021-43577

Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 5.1.1
Fix from $1,950 2021-11-12
Fortiportal HIGH 8.1
CVE-2021-36172

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attack…

Fix: 5.3.7 / 6.0.6+
Fix from $1,950 2021-11-02