Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Hcl Commerce CRITICAL 9.1
CVE-2021-27741

" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"

Fix: after 9.1.5
Fix from $2,300 2021-08-13
Cpanel HIGH 7.2
CVE-2021-38584

The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

Fix: 98.0.1+
Fix from $1,950 2021-08-11
Mobiletogether Server CRITICAL 9.1
CVE-2021-37425EPSS 66%

Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobi…

Fix: 7.3+
Fix from $2,300 2021-08-10
Solid Edge Se2021 Firmware MEDIUM 5.5
CVE-2021-37178

A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying…

Mitigation only
Fix from $1,600 2021-08-10
Mule HIGH 7.5
CVE-2021-1630

XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pi…

Fix: 4.3.0+
Fix from $1,950 2021-08-05
Opinio MEDIUM 6.5
CVE-2020-26564

ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic sur…

Fix: 7.15+
Fix from $1,600 2021-07-31
Glances CRITICAL 9.8
CVE-2021-23418

The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is kno…

Fix: 3.2.1+
Fix from $2,300 2021-07-29
Qradar Security Information And Event Manager CRITICAL 9.1
CVE-2021-20399

IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…

Fix: 7.3.3 / 7.4.3+
Fix from $2,300 2021-07-27
Verastream Host Integrator HIGH 7.6
CVE-2021-22523

XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability c…

Fix: 7.8+
Fix from $1,950 2021-07-22
Bi Publisher MEDIUM 5.3
CVE-2021-2401EPSS 85%

Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affecte…

Mitigation only
Fix from $1,600 2021-07-21
Emc Openmanage Enterprise HIGH 8.1
CVE-2020-5323

Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v…

Fix: 1.10.00 / 3.2+
Fix from $1,950 2021-07-19
Emc Avamar Server HIGH 8.2
CVE-2019-3752

Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2…

Patch available
Fix from $1,950 2021-07-16
G 50a Firmware HIGH 8.2
CVE-2021-20595

Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver…

Fix: after 7.09
Fix from $1,950 2021-07-13
Flowdroid MEDIUM 5.3
CVE-2021-32754

FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attack…

Fix: 2.9.0+
Fix from $1,600 2021-07-12
Vsa HIGH 7.5
CVE-2021-30201EPSS 25%

The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet…

Fix: 9.5.6+
Fix from $1,950 2021-07-09
Fpwin Pro MEDIUM 5.5
CVE-2021-32972

Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access…

Fix: after 7.5.1.1
Fix from $1,600 2021-07-09
\ HIGH 7.5
CVE-2012-1102

It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted so…

Fix: 0.39+
Fix from $1,950 2021-07-09
Xml2dict HIGH 7.5
CVE-2021-25951

XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.

No fix yet
Fix from $1,950 2021-06-30
Ecns280 Firmware MEDIUM 5.3
CVE-2021-22338

There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML messa…

Mitigation only
Fix from $1,600 2021-06-29
Service Api HIGH 7.5
CVE-2021-29620

Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortun…

Fix: 5.4.0+
Fix from $1,950 2021-06-23
Automate CRITICAL 9.8
CVE-2021-35066

An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.

Fix: 2021.0.6.132+
Fix from $2,300 2021-06-21
Solr HIGH 7.5
CVE-2021-33813EPSS 19%

An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.

Fix: after 2.0.6
Fix from $1,950 2021-06-16
Financial Transaction Manager CRITICAL 9.1
CVE-2020-5003

IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…

Mitigation only
Fix from $2,300 2021-06-11
Netweaver Application Server For Java MEDIUM 6.5
CVE-2021-27635

SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network an…

Patch available
Fix from $1,600 2021-06-09
Cognos Analytics HIGH 7.1
CVE-2019-4730

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Patch available
Fix from $1,950 2021-06-01
Cognos Analytics HIGH 8.2
CVE-2020-4300

IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Patch available
Fix from $1,950 2021-06-01
Crosscadware MEDIUM 5.5
CVE-2021-27492

When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dRe…

Fix: after 2021.1
Fix from $1,600 2021-05-27
Websphere Application Server HIGH 8.2
CVE-2021-20492

IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing…

Fix: after 21.0.0.5
Fix from $1,950 2021-05-26
Chamilo MEDIUM 6.5
CVE-2021-32925

admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.

Fix: after 1.11.16
Fix from $1,600 2021-05-13
Elastic App Search HIGH 7.5
CVE-2021-22140

Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe…

Fix: 7.12.0+
Fix from $1,950 2021-05-13