Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Windows 10 HIGH 7.5
CVE-2019-1057

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp…

Patch available
Fix from $1,950 2019-08-14
Enable Now MEDIUM 5.4
CVE-2019-0340

The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulner…

Fix: 1902+
Fix from $1,600 2019-08-14
Manageengine Assetexplorer HIGH 8.1
CVE-2019-14693

Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac…

Mitigation only
Fix from $1,950 2019-08-08
3cx HIGH 7.5
CVE-2019-13176

An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affe…

No fix yet
Fix from $1,950 2019-08-08
The Scheduler HIGH 7.5
CVE-2018-14383

The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the ve…

Mitigation only
Fix from $1,950 2019-08-07
Cpanel MEDIUM 6.3
CVE-2017-18438

cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
I2 Intelligent Analysis Platform HIGH 7.1
CVE-2019-4062

IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.1.1
Fix from $1,950 2019-07-30
Daeja Viewone HIGH 7.1
CVE-2019-4456

IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Fix: after 5.0.6
Fix from $1,950 2019-07-30
Cloud Backup Suite HIGH 7.2
CVE-2019-10264

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen ha…

Fix: 8.1.1.50+
Fix from $1,950 2019-07-26
Cloud Backup Suite HIGH 7.5
CVE-2019-10266EPSS 13%

An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the …

Fix: 8.1.1.50+
Fix from $1,950 2019-07-26
Tomee CRITICAL 9.8
CVE-2019-13990EPSS 16%

initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.

Fix: 2.3.2+
Fix from $2,300 2019-07-26
Electric Fr Configurator2 Firmware MEDIUM 5.5
CVE-2019-10976

Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized w…

Fix: 1.16s+
Fix from $1,600 2019-07-26
Jeesite MEDIUM 6.5
CVE-2019-1010202

Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function…

No fix yet
Fix from $1,600 2019-07-23
Campaign HIGH 7.5
CVE-2019-7847

Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability.…

Fix: after 18.10.5.8984
Fix from $1,950 2019-07-18
Ladon CRITICAL 9.8
CVE-2019-1010268EPSS 6%

Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, …

Fix: after 0.9.40
Fix from $2,300 2019-07-18
Ghidra CRITICAL 9.1
CVE-2019-13625

NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.

Fix: 9.0.1+
Fix from $2,300 2019-07-17
Cache MEDIUM 6.4
CVE-2018-17152

Intersystems Cache 2017.2.2.865.0 allows XXE.

No fix yet
Fix from $1,600 2019-07-11
Mailenable CRITICAL 9.8
CVE-2019-12924

MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.…

Fix: 6.90 / 7.62+
Fix from $2,300 2019-07-08
Opencats HIGH 7.5
CVE-2019-13358EPSS 24%

lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus…

Fix: 0.9.4-3+
Fix from $1,950 2019-07-05
Codeigniter Restserver CRITICAL 9.8
CVE-2015-3907

CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.

No fix yet
Fix from $2,300 2019-07-03
Debian Linux HIGH 8.1
CVE-2019-13031

LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific…

Fix: 1.9.20+
Fix from $1,950 2019-06-28
Gradle HIGH 7.5
CVE-2019-9843

In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over …

Fix: 1.20.0 / 3.20.0+
Fix from $1,950 2019-06-28
Ubuntu Linux HIGH 7.5
CVE-2018-20843EPSS 7%

In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amoun…

Fix: 2.2.7+
Fix from $1,950 2019-06-24
Blogengine.net HIGH 7.5
CVE-2019-11392

BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.

Fix: after 3.3.7
Fix from $1,950 2019-06-21
Blogengine.net HIGH 7.5
CVE-2019-10718

BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackH…

Fix: after 3.3.7.0
Fix from $1,950 2019-06-21
Security Manager CRITICAL 9.1
CVE-2019-1903

A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of servic…

Mitigation only
Fix from $2,300 2019-06-20
Bubbleupnp CRITICAL 9.8
CVE-2018-15506

In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remo…

Mitigation only
Fix from $2,300 2019-06-19
Securetrack CRITICAL 9.9
CVE-2018-18406

An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerabili…

No fix yet
Fix from $2,300 2019-06-19
Hipserv CRITICAL 9.8
CVE-2018-18471EPSS 8%

/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can…

No fix yet
Fix from $2,300 2019-06-19
Infosphere Information Server HIGH 7.1
CVE-2018-1845

IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo…

Patch available
Fix from $1,950 2019-06-17