Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Ozeki Ng Sms Gateway HIGH 7.5
CVE-2020-14029

An issue was discovered in Ozeki NG SMS Gateway through 4.17.6. The RSS To SMS module processes XML files in an unsafe manner. This opens the applica…

Fix: after 4.17.6
Fix from $1,950 2020-09-18
Dotplant2 HIGH 7.5
CVE-2020-25750

An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the c…

Fix: 2020-09-14+
Fix from $1,950 2020-09-18
Yed CRITICAL 9.8
CVE-2020-25215

yWorks yEd Desktop before 3.20.1 allows XXE attacks via an XML or GraphML document.

Fix: 3.20.1+
Fix from $2,300 2020-09-17
Cocoon HIGH 7.5
CVE-2020-11991EPSS 72%

When using the StreamGenerator, the code parse a user-provided XML. A specially crafted XML, including external system entities, could be used to acc…

Fix: after 2.1.12
Fix from $1,950 2020-09-11
Onbase CRITICAL 9.8
CVE-2020-25257

An issue was discovered in Hyland OnBase 16.0.2.83 and below, 17.0.2.109 and below, 18.0.0.37 and below, 19.8.16.1000 and below and 20.3.10.1000 and …

Fix: after 20.3.10.1000
Fix from $2,300 2020-09-11
Expresscluster X HIGH 7.5
CVE-2020-17408EPSS 74%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is n…

Patch available
Fix from $1,950 2020-09-10
Ubuntu Linux CRITICAL 9.8
CVE-2020-24379

WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.

Fix: after 2.0.7
Fix from $2,300 2020-09-09
Valgrind HIGH 7.1
CVE-2020-2245

Jenkins Valgrind Plugin 0.28 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 0.28
Fix from $1,950 2020-09-01
Klocwork Analysis MEDIUM 6.5
CVE-2020-2247

Jenkins Klocwork Analysis Plugin 2020.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 2020.2.1
Fix from $1,600 2020-09-01
Mpxj CRITICAL 9.8
CVE-2020-25020

MPXJ through 8.1.3 allows XXE attacks. This affects the GanttProjectReader and PhoenixReader components.

Fix: after 17.12
Fix from $2,300 2020-08-29
Nova HIGH 8.3
CVE-2020-17376

An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a so…

Fix: 19.3.1 / 20.3.1+
Fix from $1,950 2020-08-26
Maltego MEDIUM 6.5
CVE-2020-24656

Maltego before 4.2.12 allows XXE attacks.

Fix: 4.2.12+
Fix from $1,600 2020-08-26
Api Manager MEDIUM 6.5
CVE-2020-24591

The Management Console in certain WSO2 products allows XXE attacks during EventReceiver updates. This affects API Manager through 3.0.0, API Manager …

Fix: after 5.6.0
Fix from $1,600 2020-08-21
Api Manager CRITICAL 9.1
CVE-2020-24589EPSS 26%

The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML External Entity injection (XXE) attacks.

Fix: after 3.1.0
Fix from $2,300 2020-08-21
Exvf5c 2 Firmware CRITICAL 9.1
CVE-2020-24052

Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbi…

No fix yet
Fix from $2,300 2020-08-21
Urbancode Deploy HIGH 8.2
CVE-2020-4481

IBM UrbanCode Deploy (UCD) 6.2.7.3, 6.2.7.4, 7.0.3.0, and 7.0.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML …

Mitigation only
Fix from $1,950 2020-08-05
Cognos Analytics CRITICAL 9.1
CVE-2020-4377

IBM Cognos Anaytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could ex…

Mitigation only
Fix from $2,300 2020-08-03
Maximo Asset Management HIGH 8.2
CVE-2020-4463EPSS 32%

IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote att…

Patch available
Fix from $1,950 2020-07-29
One Firmware HIGH 7.5
CVE-2020-15419EPSS 60%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…

Fix: 9.5.4.4587 / 10.0.0.750+
Fix from $1,950 2020-07-28
One Firmware HIGH 7.5
CVE-2020-15418EPSS 9%

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Veeam ONE 10.0.0.750_20200415. Authenticati…

Fix: 9.5.4.4587 / 10.0.0.750+
Fix from $1,950 2020-07-28
Sd Wan Firmware HIGH 7.3
CVE-2020-3405

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to informa…

Fix: after 19.2.2
Fix from $1,950 2020-07-16
Sterling External Authentication Server HIGH 8.2
CVE-2020-4462

IBM Sterling External Authentication Server 6.0.1, 6.0.0, 2.4.3.2, and 2.4.2 and IBM Sterling Secure Proxy 6.0.1, 6.0.0, 3.4.3, and 3.4.2 are vulnera…

Mitigation only
Fix from $1,950 2020-07-16
I Net Clear Reports CRITICAL 9.8
CVE-2020-12684

XXE injection can occur in i-net Clear Reports 2019 19.0.287 (Designer), as used in i-net HelpDesk and other products, when XML input containing a re…

Mitigation only
Fix from $2,300 2020-07-15
Debian Linux HIGH 7.1
CVE-2019-17637

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to …

Fix: after 3.18
Fix from $1,950 2020-07-15
Qradar Security Information And Event Manager MEDIUM 5.5
CVE-2020-4510

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Fix: after 7.3.2
Fix from $1,600 2020-07-14
Cpu Module Logging Configuration Tool HIGH 7.5
CVE-2020-5602

Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. 1.94Y and earlier, CW Configurator Ver. 1.010L and earlier, …

Fix: after 1.590q
Fix from $1,950 2020-06-30
Tuxguitar HIGH 7.5
CVE-2020-14940

An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. It uses misconfigured XML parsers, leading to XXE while loading GP6 (.gp…

Patch available
Fix from $1,950 2020-06-23
Webfocus Business Intelligence HIGH 8.2
CVE-2020-14204

In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTT…

Mitigation only
Fix from $1,950 2020-06-22
Open Xchange Appsuite MEDIUM 6.5
CVE-2020-8541

OX App Suite through 7.10.3 allows XXE attacks.

No fix yet
Fix from $1,600 2020-06-16
Api Manager MEDIUM 6.7
CVE-2020-13883

In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE durin…

Fix: after 5.9.0
Fix from $1,600 2020-06-06