Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Solutions Business Manager HIGH 8.0
CVE-2019-18943

Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations.

Fix: 11.7.1+
Fix from $1,950 2021-02-26
Digital Sentry Server HIGH 7.5
CVE-2021-27184

Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting …

No fix yet
Fix from $1,950 2021-02-11
Websphere Application Server HIGH 8.2
CVE-2021-20353EPSS 5%

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: 7.0.0.45 / 8.0.0.15+
Fix from $1,950 2021-02-10
Openhab MEDIUM 5.0
CVE-2021-21266

openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML extern…

Fix: 2.5.12+
Fix from $1,600 2021-02-01
Websphere Application Server HIGH 8.2
CVE-2020-4949

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.5.6
Fix from $1,950 2021-01-26
Nutch CRITICAL 9.1
CVE-2021-23901

An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa…

Fix: 1.18+
Fix from $2,300 2021-01-25
D2d HIGH 7.5
CVE-2020-27858EPSS 74%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not…

Mitigation only
Fix from $1,950 2021-01-20
Application Lifecycle Management HIGH 8.1
CVE-2021-22498

XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnera…

Fix: after 15.0.1
Fix from $1,950 2021-01-19
Json Sanitizer CRITICAL 9.8
CVE-2021-23899

OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbi…

Fix: 1.2.2+
Fix from $2,300 2021-01-13
Jt2go MEDIUM 6.5
CVE-2020-26981

A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially cr…

Fix: 13.1.0+
Fix from $1,600 2021-01-12
Ebx Add Ons HIGH 7.1
CVE-2020-27148

The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO …

Fix: after 4.4.2
Fix from $1,950 2021-01-12
Plone HIGH 8.8
CVE-2020-28734

Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.

Fix: 5.2.3+
Fix from $1,950 2020-12-30
Plone HIGH 8.8
CVE-2020-28736

Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, onl…

Fix: 5.2.3+
Fix from $1,950 2020-12-30
Web Time And Attendance CRITICAL 9.8
CVE-2020-35604

An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.

No fix yet
Fix from $2,300 2020-12-21
Collaboration MEDIUM 6.5
CVE-2020-35123

In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store exten…

Fix: 8.8.15+
Fix from $1,600 2020-12-17
Nexus Repository Manager MEDIUM 6.5
CVE-2020-29436

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of …

Fix: 3.29.0+
Fix from $1,600 2020-12-17
Codebeamer MEDIUM 5.5
CVE-2020-26513

An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import project…

Fix: 10.1.0+
Fix from $1,600 2020-12-07
Fedora HIGH 7.5
CVE-2020-25649EPSS 18%

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML extern…

Fix: 0.12.0 / 2.6.7.4+
Fix from $1,950 2020-12-03
Cvs HIGH 7.5
CVE-2020-2324

Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2.16
Fix from $1,950 2020-12-03
Webreports HIGH 8.8
CVE-2020-7572

A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that co…

Fix: after 3.1
Fix from $1,950 2020-11-19
Aura System Manager MEDIUM 6.5
CVE-2020-7032

An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side r…

Fix: 8.1.3+
Fix from $1,600 2020-11-13
Quartus Prime HIGH 7.5
CVE-2020-24454

Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(…

Fix: 20.3+
Fix from $1,950 2020-11-12
Connect Secure HIGH 7.2
CVE-2020-15352

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authen…

Fix: after 9.0
Fix from $1,950 2020-10-27
Levistudiou HIGH 7.5
CVE-2020-25186

An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure.

Fix: after 2019-09-21
Fix from $1,950 2020-10-22
Curam Social Program Management HIGH 8.1
CVE-2020-4772

An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit…

Mitigation only
Fix from $1,950 2020-10-12
Print CRITICAL 9.1
CVE-2020-15232

In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style.

Fix: 3.24+
Fix from $2,300 2020-10-02
Nifi MEDIUM 5.5
CVE-2020-13940

In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini…

Fix: after 1.11.4
Fix from $1,600 2020-10-01
Halo CRITICAL 9.1
CVE-2020-21524

There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/word…

No fix yet
Fix from $2,300 2020-09-30
Liquibase Runner HIGH 7.1
CVE-2020-2284

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.4.5
Fix from $1,950 2020-09-23
Websphere Application Server HIGH 7.5
CVE-2020-4643

IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.5.5
Fix from $1,950 2020-09-21