Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Intellij Idea HIGH 7.5
CVE-2021-30006

In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.

Fix: 2020.3.3+
Fix from $1,950 2021-05-11
Paxstore MEDIUM 6.5
CVE-2020-36124

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise …

Fix: after 7.0.8_20200511171508
Fix from $1,600 2021-05-07
Broadworks Messaging Server HIGH 7.1
CVE-2021-1530

A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to …

Mitigation only
Fix from $1,950 2021-05-06
Qradar Security Information And Event Manager HIGH 8.1
CVE-2020-5013

IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2021-05-05
Firepower Device Manager MEDIUM 5.4
CVE-2021-1369

A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read an…

Fix: 6.5.0.5 / 6.6.3+
Fix from $1,600 2021-04-29
Clearpass HIGH 8.2
CVE-2021-29140

A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Arub…

Fix: 6.7.13 / 6.8.4+
Fix from $1,950 2021-04-29
Airwave HIGH 8.1
CVE-2021-25163

A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…

Fix: 8.2.12.1+
Fix from $1,950 2021-04-29
Equinox Conferencing HIGH 8.1
CVE-2020-7037

An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to…

Fix: 9.1.11+
Fix from $1,950 2021-04-28
Airwave MEDIUM 6.5
CVE-2021-25164

A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…

Fix: 8.2.12.1+
Fix from $1,600 2021-04-28
Airwave HIGH 8.1
CVE-2021-25165

A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…

Fix: 8.2.12.1+
Fix from $1,950 2021-04-28
Aura Orchestration Designer MEDIUM 6.5
CVE-2020-7035

An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote…

Fix: after 7.2.2
Fix from $1,600 2021-04-23
Callback Assist MEDIUM 6.5
CVE-2020-7036

An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that …

Fix: 4.7.1.1+
Fix from $1,600 2021-04-23
Saml V2 MEDIUM 6.5
CVE-2021-27736

FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers…

Fix: 0.5.4+
Fix from $1,600 2021-04-22
Config File Provider HIGH 8.1
CVE-2021-21642EPSS 38%

Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 3.7.0
Fix from $1,950 2021-04-21
Websphere Application Server HIGH 8.2
CVE-2021-20454

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem…

Fix: after 9.0.5.7
Fix from $1,950 2021-04-21
Websphere Application Server HIGH 8.2
CVE-2021-20453

IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…

Fix: 8.0.0.15 / 8.5.5.20+
Fix from $1,950 2021-04-20
WordPress MEDIUM 6.5
CVE-2021-29447EPSS 86%

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leadi…

Fix: 5.7.1+
Fix from $1,600 2021-04-15
Netweaver Process Integration MEDIUM 6.5
CVE-2021-27604

In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Reposi…

Mitigation only
Fix from $1,600 2021-04-14
Data Loss Prevention HIGH 7.5
CVE-2020-6590

Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

Fix: 8.5.4 / 8.7.1+
Fix from $1,950 2021-04-08
Insider Threat Management HIGH 7.2
CVE-2021-22158

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. …

Fix: 7.9.3 / 7.10.3+
Fix from $1,950 2021-04-06
Fedora HIGH 7.5
CVE-2021-29421

models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.

Fix: after 2.9.2
Fix from $1,950 2021-04-01
Engineering Insights HIGH 7.1
CVE-2021-20502

IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploi…

Patch available
Fix from $1,950 2021-03-30
Cloud Pak For Automation HIGH 7.1
CVE-2021-20482

IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo…

Mitigation only
Fix from $1,950 2021-03-30
Mule CRITICAL 9.8
CVE-2021-1628

MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub a…

Fix: after 4.2.2
Fix from $2,300 2021-03-26
Tranzware E Commerce Payment Gateway HIGH 7.5
CVE-2021-28110

/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

Fix: 3.1.27.5+
Fix from $1,950 2021-03-19
Solid Edge MEDIUM 5.5
CVE-2020-28387

A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a sp…

Mitigation only
Fix from $1,600 2021-03-15
Airwave MEDIUM 6.5
CVE-2021-26969

A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to…

Fix: 8.2.12.0+
Fix from $1,600 2021-03-05
Lumis Experience Platform CRITICAL 9.1
CVE-2021-27931EPSS 18%

LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a re…

Fix: 10.0.0+
Fix from $2,300 2021-03-03
Eprints CRITICAL 9.8
CVE-2021-26703

EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.

Patch available
Fix from $2,300 2021-03-01
Emc Srs Policy Manager HIGH 7.2
CVE-2021-21517

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supp…

Mitigation only
Fix from $1,950 2021-03-01