Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Office Server Document Converter HIGH 7.5
CVE-2021-20838

Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti…

Fix: 5.2+
Fix from $1,950 2021-11-01
Office Server Document Converter MEDIUM 6.5
CVE-2021-20839

Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti…

Fix: 5.2+
Fix from $1,600 2021-11-01
Easyxml CRITICAL 9.1
CVE-2020-26705

The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensi…

Patch available
Fix from $2,300 2021-10-31
Modx Revolution CRITICAL 9.1
CVE-2020-25911

A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information di…

Patch available
Fix from $2,300 2021-10-31
Symphony CRITICAL 9.1
CVE-2020-25912

A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an informa…

Mitigation only
Fix from $2,300 2021-10-31
Corenlp HIGH 7.5
CVE-2021-3869

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Fix: after 4.3.0
Fix from $1,950 2021-10-19
Corenlp CRITICAL 9.8
CVE-2021-3878

corenlp is vulnerable to Improper Restriction of XML External Entity Reference

Fix: 4.3.1+
Fix from $2,300 2021-10-15
S Cms HIGH 7.5
CVE-2020-19954

An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

No fix yet
Fix from $1,950 2021-10-14
Remote Service Manager MEDIUM 6.5
CVE-2021-20801

Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information s…

Mitigation only
Fix from $1,600 2021-10-13
Jasperreports Server HIGH 7.5
CVE-2021-35496

The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO Jas…

Fix: after 7.9.0
Fix from $1,950 2021-10-12
Businessobjects Business Intelligence Platform HIGH 7.5
CVE-2021-40500

SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v…

Mitigation only
Fix from $1,950 2021-10-12
Opencms MEDIUM 6.5
CVE-2021-3312

An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfil…

No fix yet
Fix from $1,600 2021-10-08
Manageengine Admanager Plus CRITICAL 9.8
CVE-2021-38298

Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.

Fix: 7.1+
Fix from $2,300 2021-10-07
Openoffice MEDIUM 6.5
CVE-2021-40439

Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia…

Fix: after 4.1.10
Fix from $1,600 2021-10-07
Pingfederate HIGH 7.5
CVE-2021-41770

Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.

Fix: 10.3.1+
Fix from $1,950 2021-10-07
Identity Services Engine MEDIUM 5.4
CVE-2021-34706

A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access…

Fix: after 3.1
Fix from $1,600 2021-10-06
Ngeniusone MEDIUM 6.5
CVE-2021-35201

NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.

Mitigation only
Fix from $1,600 2021-09-30
Nokogiri HIGH 7.5
CVE-2021-41098

Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby onl…

Fix: 1.12.5+
Fix from $1,950 2021-09-27
Jazz For Service Management HIGH 8.1
CVE-2021-29831

IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when proce…

Patch available
Fix from $1,950 2021-09-21
Jena HIGH 7.5
CVE-2021-39239

A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…

Fix: after 4.1.0
Fix from $1,950 2021-09-16
Assyst HIGH 8.2
CVE-2021-30137

Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It …

No fix yet
Fix from $1,950 2021-09-15
Teamcenter Visualization HIGH 7.5
CVE-2021-40356

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…

Fix: 12.4.0.8 / 13.0.0.7+
Fix from $1,950 2021-09-14
Any23 CRITICAL 9.1
CVE-2021-38555

An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…

Fix: 2.5+
Fix from $2,300 2021-09-11
Pan Os MEDIUM 6.5
CVE-2021-3055

An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated …

Fix: 8.1.20 / 9.0.14+
Fix from $1,600 2021-09-08
Theia CRITICAL 9.8
CVE-2021-34436

In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. T…

Fix: after 0.2.0
Fix from $2,300 2021-09-02
Nested View HIGH 7.1
CVE-2021-21680

Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.

Fix: after 1.20
Fix from $1,950 2021-08-31
Debian Linux HIGH 7.5
CVE-2021-39371

An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a pat…

Fix: 4.4.5+
Fix from $1,950 2021-08-23
Quokka CRITICAL 9.8
CVE-2020-18703

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.

Patch available
Fix from $2,300 2021-08-16
Quokka CRITICAL 9.8
CVE-2020-18705

XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.

Patch available
Fix from $2,300 2021-08-16
Screenshare CRITICAL 9.1
CVE-2021-34823

The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows una…

Fix: 2.0+
Fix from $2,300 2021-08-13