Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Postgresql Jdbc Driver HIGH 7.7
CVE-2020-13692

PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.

Fix: 42.2.13+
Fix from $1,950 2020-06-04
Qradar Security Information And Event Manager HIGH 7.6
CVE-2020-4509

IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …

Mitigation only
Fix from $1,950 2020-06-04
Security Identity Governance And Intelligence HIGH 7.1
CVE-2020-4246

IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Patch available
Fix from $1,950 2020-05-28
Pan Os HIGH 7.5
CVE-2020-2012

Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthent…

Fix: 8.1.13 / 9.0.7+
Fix from $1,950 2020-05-13
Log4net CRITICAL 9.8
CVE-2018-1285EPSS 17%

Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…

Fix: 2.0.10+
Fix from $2,300 2020-05-11
Snagit MEDIUM 5.5
CVE-2020-11541

In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data u…

Fix: after 20.0.3
Fix from $1,600 2020-05-08
Api Manager HIGH 7.2
CVE-2020-12719

XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, A…

Fix: after 6.4.0
Fix from $1,950 2020-05-08
Service Api HIGH 7.5
CVE-2020-12642

An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSR…

Fix: 4.3.12 / 5.1.1+
Fix from $1,950 2020-05-04
Ubuntu Linux CRITICAL 9.8
CVE-2020-10683EPSS 7%

dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…

Fix: 2.0.3 / 2.1.3+
Fix from $2,300 2020-05-01
Enterprise Integrator HIGH 7.2
CVE-2020-11885

WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend…

Fix: after 6.6.0
Fix from $1,950 2020-04-17
Parasoft Findings HIGH 7.1
CVE-2020-2178

Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 10.4.3
Fix from $1,950 2020-04-16
Commerce Cloud CRITICAL 9.3
CVE-2020-6238

SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing …

Mitigation only
Fix from $2,300 2020-04-14
Webaccess\/nms HIGH 7.5
CVE-2020-10629

WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.

Fix: 3.0.2+
Fix from $1,950 2020-04-09
Appscan HIGH 8.2
CVE-2019-4391

HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data

Fix: after 9.0.3.14
Fix from $1,950 2020-04-07
Cipace CRITICAL 9.8
CVE-2020-11586

An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XM…

Fix: 9.1+
Fix from $2,300 2020-04-06
Mercury CRITICAL 9.8
CVE-2020-10990

An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.

Fix: 1.12.28+
Fix from $2,300 2020-03-27
Aplkit CRITICAL 9.8
CVE-2020-10991

Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java

Fix: after 1.3.0
Fix from $2,300 2020-03-27
Azkaban CRITICAL 9.8
CVE-2020-10992

Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.

Fix: after 3.84.0
Fix from $2,300 2020-03-27
Osmand CRITICAL 9.1
CVE-2020-10993

Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.

Fix: after 2.0.0
Fix from $2,300 2020-03-27
Rapiddeploy HIGH 8.8
CVE-2020-2171

Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 4.2
Fix from $1,950 2020-03-25
Autoupdater.net CRITICAL 9.8
CVE-2019-20627

AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.

Fix: 1.5.8+
Fix from $2,300 2020-03-23
Svglib CRITICAL 9.8
CVE-2020-10799

The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.

Fix: after 0.9.3
Fix from $2,300 2020-03-20
Oxygen Xml Author HIGH 7.5
CVE-2019-20191

Oxygen XML Editor 21.1.1 allows XXE to read any file.

Fix: after 21.1.1
Fix from $1,950 2020-03-16
Manageengine Desktop Central CRITICAL 9.8
CVE-2020-8540EPSS 13%

An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …

Fix: 2020-03-07+
Fix from $2,300 2020-03-11
Metasys Application And Data Server CRITICAL 9.1
CVE-2020-9044

XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII serve…

Fix: after 13.2
Fix from $2,300 2020-03-10
Rundeck HIGH 7.1
CVE-2020-2144

Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 3.6.6
Fix from $1,950 2020-03-09
Cobertura HIGH 7.1
CVE-2020-2138

Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

Fix: after 1.15
Fix from $1,950 2020-03-09
Smartclient CRITICAL 9.8
CVE-2020-9352

An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST reques…

No fix yet
Fix from $2,300 2020-02-23
Spacewalk CRITICAL 9.8
CVE-2020-1693

A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …

Fix: 2.9+
Fix from $2,300 2020-02-17
Xclarity Administrator MEDIUM 5.5
CVE-2019-6194

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow i…

Fix: 2.6.6+
Fix from $1,600 2020-02-14