Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Manageengine Servicedesk Plus HIGH 8.8
CVE-2017-9362

ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.

Fix: 9.3+
Fix from $1,950 2019-03-25
Athoc MEDIUM 5.9
CVE-2019-8997

An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could al…

Fix: 7.6_hf-567+
Fix from $1,600 2019-03-21
Phpshe HIGH 7.5
CVE-2019-9761

An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This…

No fix yet
Fix from $1,950 2019-03-14
Hana Extended Application Services MEDIUM 6.5
CVE-2019-0277

SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer w…

Mitigation only
Fix from $1,600 2019-03-12
Nablarch CRITICAL 9.1
CVE-2019-5918

Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

Mitigation only
Fix from $2,300 2019-03-12
Debian Linux MEDIUM 5.3
CVE-2019-9658

Checkstyle before 8.18 loads external DTDs by default.

Fix: 8.18+
Fix from $1,600 2019-03-11
Infosphere Information Server CRITICAL 9.1
CVE-2018-1727

IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…

Mitigation only
Fix from $2,300 2019-02-15
Pmd HIGH 8.1
CVE-2019-7722

PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (ei…

Fix: after 5.8.1
Fix from $1,950 2019-02-11
Job Import CRITICAL 9.1
CVE-2019-1003015

An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport…

Fix: after 2.1
Fix from $2,300 2019-02-06
App Connect MEDIUM 5.3
CVE-2018-1801

IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and We…

Fix: after 11.0.0.1
Fix from $1,600 2019-02-04
Security Access Manager HIGH 7.1
CVE-2018-1970

IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…

Fix: after 7.0.1.10
Fix from $1,950 2019-02-04
Princexml HIGH 8.6
CVE-2018-19858

PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencin…

Fix: after 10.0
Fix from $1,950 2019-01-30
Spring Web Services CRITICAL 9.8
CVE-2019-3773

Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…

Fix: after 8.1.0
Fix from $2,300 2019-01-18
Spring Batch CRITICAL 9.8
CVE-2019-3774

Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML…

Fix: after 4.0.1
Fix from $2,300 2019-01-18
Spring Integration CRITICAL 9.8
CVE-2019-3772

Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were s…

Fix: after 5.1.1
Fix from $2,300 2019-01-18
Universal Plugin Manager MEDIUM 6.5
CVE-2018-20233

The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privile…

Fix: 2.22.14+
Fix from $1,600 2019-01-18
Security Identity Manager HIGH 7.1
CVE-2018-2019

IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…

Patch available
Fix from $1,950 2019-01-18
Web Infrastructure Platform HIGH 7.5
CVE-2018-20733

BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

Fix: 9.4+
Fix from $1,950 2019-01-17
Mailenable CRITICAL 10.0
CVE-2015-9280

MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.

Fix: 8.60+
Fix from $2,300 2019-01-16
Logontracer HIGH 8.8
CVE-2018-16166

LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

Fix: after 1.2.0
Fix from $1,950 2019-01-09
Server CRITICAL 9.8
CVE-2019-5748

In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.

Patch available
Fix from $2,300 2019-01-09
Karaf CRITICAL 9.8
CVE-2018-11788EPSS 7%

Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …

Fix: 4.1.7+
Fix from $2,300 2019-01-07
Wxjava CRITICAL 9.8
CVE-2019-5312

An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: th…

Fix: 3.4.0+
Fix from $2,300 2019-01-04
Manageengine Adselfservice Plus CRITICAL 9.8
CVE-2018-20664EPSS 8%

Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

Mitigation only
Fix from $2,300 2019-01-03
Web Content Manager MEDIUM 6.5
CVE-2018-19371EPSS 6%

The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

No fix yet
Fix from $1,600 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 8%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Logisim Evolution HIGH 8.8
CVE-2018-1000889

Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom i…

Fix: after 2.14.3
Fix from $1,950 2018-12-28
Iiot Monior HIGH 7.5
CVE-2018-7837

An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that co…

Mitigation only
Fix from $1,950 2018-12-24
Debian Linux CRITICAL 9.8
CVE-2018-20433

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Patch available
Fix from $2,300 2018-12-24
Wxjava CRITICAL 9.8
CVE-2018-20318

An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.

No fix yet
Fix from $2,300 2018-12-21