Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Elasticsearch MEDIUM 5.9
CVE-2018-17247

Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw…

Mitigation only
Fix from $1,600 2018-12-20
Retrofit CRITICAL 9.1
CVE-2018-1000844

Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JA…

Fix: 2.5.0+
Fix from $2,300 2018-12-20
Freecol CRITICAL 10.0
CVE-2018-1000825

FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of …

Fix: after 2018-08-22
Fix from $2,300 2018-12-20
Frostwire CRITICAL 9.0
CVE-2018-1000828

FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can res…

Mitigation only
Fix from $2,300 2018-12-20
Anyplace CRITICAL 9.0
CVE-2018-1000829

Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Dis…

Mitigation only
Fix from $2,300 2018-12-20
Xr3player CRITICAL 10.0
CVE-2018-1000830

XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data,…

Fix: after 3.124
Fix from $2,300 2018-12-20
K 9 Mail CRITICAL 10.0
CVE-2018-1000831

K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential d…

Fix: after 5.600
Fix from $2,300 2018-12-20
Runelite CRITICAL 9.0
CVE-2018-1000834

runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can re…

Fix: after 1.4.23
Fix from $2,300 2018-12-20
Keepass Dx CRITICAL 10.0
CVE-2018-1000835

KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidenti…

Mitigation only
Fix from $2,300 2018-12-20
Bw Calendar Engine CRITICAL 9.0
CVE-2018-1000836

bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can res…

Fix: after 3.12.0
Fix from $2,300 2018-12-20
Uml Designer CRITICAL 10.0
CVE-2018-1000837

UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confident…

Fix: after 8.0.0
Fix from $2,300 2018-12-20
Autopsy CRITICAL 10.0
CVE-2018-1000838

autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential …

Fix: after 4.9.0
Fix from $2,300 2018-12-20
Processing MEDIUM 6.5
CVE-2018-1000840

Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in …

Fix: after 3.4
Fix from $1,600 2018-12-20
Awesome Procedures On Cyper CRITICAL 10.0
CVE-2018-1000820

neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in…

Patch available
Fix from $2,300 2018-12-20
Micromathematics CRITICAL 10.0
CVE-2018-1000821

MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure …

Fix: 2.17.3+
Fix from $2,300 2018-12-20
Fess CRITICAL 10.0
CVE-2018-1000822

codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure o…

Fix: 12.2.3+
Fix from $2,300 2018-12-20
Exist CRITICAL 10.0
CVE-2018-1000823

exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confiden…

Fix: 5.0.0+
Fix from $2,300 2018-12-20
S3 Browser MEDIUM 6.5
CVE-2018-20298

S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash…

Fix: 8.1.5+
Fix from $1,600 2018-12-19
Openrefine HIGH 7.5
CVE-2018-20157

The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t…

Fix: after 3.1
Fix from $1,950 2018-12-15
Operational Decision Manager CRITICAL 9.1
CVE-2018-1821EPSS 16%

IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…

Fix: 8.6.0.3 / 8.7.1.2+
Fix from $2,300 2018-12-13
Netweaver Application Server Java HIGH 7.1
CVE-2018-2492

SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in ver…

Mitigation only
Fix from $1,950 2018-12-11
Pippo CRITICAL 9.8
CVE-2018-20059

jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.

No fix yet
Fix from $2,300 2018-12-11
Prizmdoc CRITICAL 9.1
CVE-2018-15805

Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files…

Fix: 13.5+
Fix from $2,300 2018-12-10
Bw Webdav HIGH 7.5
CVE-2018-20000

Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/ser…

Fix: 4.0.3+
Fix from $1,950 2018-12-10
Clearpass Policy Manager HIGH 8.1
CVE-2018-7063

In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been di…

Fix: 6.6.10 / 6.7.3+
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1424

IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack…

Mitigation only
Fix from $1,950 2018-12-07
Marketing Platform HIGH 7.1
CVE-2018-1920

IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…

Mitigation only
Fix from $1,950 2018-12-07
Cimplicity CRITICAL 9.1
CVE-2018-15362

XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0

Mitigation only
Fix from $2,300 2018-12-07
Sftp\/scp Server CRITICAL 9.1
CVE-2018-16792

SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to ex…

Fix: after 2018-09-10
Fix from $2,300 2018-12-05
Qradar Security Information And Event Manager HIGH 7.1
CVE-2018-1730

IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…

Fix: after 7.3.1
Fix from $1,950 2018-12-05