Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Commandcenter Secure Gateway CRITICAL 9.8
CVE-2018-20687

An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote una…

Fix: 8.0.0+
Fix from $2,300 2019-11-18
Jboss Enterprise Application Platform HIGH 7.5
CVE-2019-10172EPSS 17%

A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c…

Fix: after 1.9.13
Fix from $1,950 2019-11-18
Xml Mapper CRITICAL 10.0
CVE-2019-14678

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local …

Mitigation only
Fix from $2,300 2019-11-14
Hornetq MEDIUM 6.5
CVE-2014-3599

HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy

Fix: after 2.4.5
Fix from $1,600 2019-11-12
Phpspreadsheet HIGH 8.8
CVE-2019-12331

PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is …

Fix: 1.8.0+
Fix from $1,950 2019-11-07
Wise Paas\/rmm HIGH 7.5
CVE-2019-18227

Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.

Fix: after 3.3.29
Fix from $1,950 2019-10-31
Labkey Server HIGH 7.5
CVE-2019-9757EPSS 37%

An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualiza…

No fix yet
Fix from $1,950 2019-10-29
Dzone Answerhub HIGH 7.5
CVE-2017-15725

An XML External Entity Injection vulnerability exists in Dzone AnswerHub.

No fix yet
Fix from $1,950 2019-10-28
Experience Manager HIGH 7.5
CVE-2019-8086EPSS 23%

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…

Mitigation only
Fix from $1,950 2019-10-25
Experience Manager HIGH 7.5
CVE-2019-8087

Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…

Mitigation only
Fix from $1,950 2019-10-25
Experience Manager HIGH 7.5
CVE-2019-8082

Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitiv…

Mitigation only
Fix from $1,950 2019-10-25
Xml Server Project HIGH 8.8
CVE-2019-18213

XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other pro…

Fix: 0.9.1+
Fix from $1,950 2019-10-23
Poi MEDIUM 5.5
CVE-2019-12415

In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can a…

Fix: after 4.1.0
Fix from $1,600 2019-10-23
360 Fireline HIGH 8.1
CVE-2019-10466

An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa…

Fix: after 1.7.2
Fix from $1,950 2019-10-23
Xnat MEDIUM 6.5
CVE-2019-14276

WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.

Patch available
Fix from $1,600 2019-10-23
Windows 10 HIGH 8.8
CVE-2019-1060EPSS 14%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…

Patch available
Fix from $1,950 2019-10-10
Unified Communications Manager MEDIUM 6.5
CVE-2019-12711

A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Editio…

Mitigation only
Fix from $1,600 2019-10-02
Appscan Source HIGH 7.1
CVE-2019-16188

HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a sp…

Fix: 9.03.13+
Fix from $1,950 2019-09-25
Limesurvey HIGH 8.8
CVE-2019-16174

An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute …

Fix: 3.17.14+
Fix from $1,950 2019-09-09
Xclarity Administrator HIGH 7.5
CVE-2019-6179

An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity I…

Fix: 2.5.0 / 6.1.0+
Fix from $1,950 2019-09-03
Storefront Server HIGH 7.5
CVE-2019-13608 KEVEPSS 30%

Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

Fix: 3.0.8000 / 3.12.4000+
Fix from $1,950 2019-08-29
Webmin MEDIUM 6.5
CVE-2019-15641

xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.

Fix: after 1.930
Fix from $1,600 2019-08-26
Tableau Server HIGH 8.1
CVE-2019-15637EPSS 14%

Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This…

Fix: after 2019.2.2
Fix from $1,950 2019-08-26
Security Access Manager For Enterprise Single Sign On HIGH 8.2
CVE-2019-4513

IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…

Mitigation only
Fix from $1,950 2019-08-26
Zenoss HIGH 7.5
CVE-2019-14258

The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.

No fix yet
Fix from $1,950 2019-08-21
Security Guardium Big Data Intelligence HIGH 8.2
CVE-2019-4340

IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…

Mitigation only
Fix from $1,950 2019-08-20
Business Automation Workflow HIGH 8.2
CVE-2019-4424

IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack …

Fix: after 19.0.0.2
Fix from $1,950 2019-08-20
Infosphere Global Name Management HIGH 8.2
CVE-2019-4433

IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (…

Mitigation only
Fix from $1,950 2019-08-20
Intelligent Operations Center HIGH 8.2
CVE-2019-4419

IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 5.2.1.1
Fix from $1,950 2019-08-20
Windows 10 MEDIUM 5.5
CVE-2019-1187

A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited t…

Patch available
Fix from $1,600 2019-08-14