Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Websphere Application Server HIGH 7.1
CVE-2018-1905

IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re…

Fix: after 9.0.0.9
Fix from $1,950 2018-11-26
Charles HIGH 8.6
CVE-2018-19244

An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file fr…

No fix yet
Fix from $1,950 2018-11-13
Energy Management Suite Software HIGH 7.3
CVE-2018-15444

A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read …

No fix yet
Fix from $1,950 2018-11-08
Syncope HIGH 7.2
CVE-2018-17186

An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file writ…

Fix: after 2.1.2
Fix from $1,950 2018-11-06
Manageengine Network Configuration Manager HIGH 7.5
CVE-2018-18980EPSS 25%

An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the …

Fix: 12.3.214+
Fix from $1,950 2018-11-06
Daeja Viewone HIGH 7.1
CVE-2018-1835

IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote…

Mitigation only
Fix from $1,950 2018-11-02
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1846

IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack whe…

Fix: after 6.0.6
Fix from $1,950 2018-11-02
Case Suite HIGH 7.5
CVE-2018-17912

An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.

Fix: after 3.10
Fix from $1,950 2018-11-02
Douchat HIGH 7.5
CVE-2018-18737

An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.

No fix yet
Fix from $1,950 2018-10-29
Udp HIGH 7.5
CVE-2018-18659

An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management…

Patch available
Fix from $1,950 2018-10-26
Security Key Lifecycle Manager HIGH 7.1
CVE-2018-1747

IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r…

Fix: after 3.0.0.1
Fix from $1,950 2018-10-15
Filenet Content Manager HIGH 7.1
CVE-2018-1844

IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

Patch available
Fix from $1,950 2018-10-12
Vert.x CRITICAL 9.8
CVE-2018-12544

In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against X…

Patch available
Fix from $2,300 2018-10-10
Sql Server Management Studio MEDIUM 5.5
CVE-2018-8527EPSS 23%

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a refere…

Patch available
Fix from $1,600 2018-10-10
Sql Server Management Studio MEDIUM 5.5
CVE-2018-8532EPSS 23%

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refer…

Patch available
Fix from $1,600 2018-10-10
Sql Server Management Studio MEDIUM 5.5
CVE-2018-8533EPSS 23%

An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refer…

Patch available
Fix from $1,600 2018-10-10
Windows 10 HIGH 8.8
CVE-2018-8494EPSS 22%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Executio…

Patch available
Fix from $1,950 2018-10-10
Tika HIGH 7.5
CVE-2018-11796EPSS 7%

In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac…

Fix: after 1.19
Fix from $1,950 2018-10-09
Levistudiou HIGH 8.8
CVE-2018-10614

An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.

Mitigation only
Fix from $1,950 2018-10-09
Pi Studio MEDIUM 5.3
CVE-2018-17889

In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParse…

Fix: after 4.2.34
Fix from $1,600 2018-10-08
Secure Access Control Server Solution Engine MEDIUM 5.7
CVE-2018-0414

A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certai…

Fix: 5.8+
Fix from $1,600 2018-10-05
Subscription Management Tool HIGH 8.1
CVE-2018-12471

A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing …

Fix: 3.0.37+
Fix from $1,950 2018-10-04
Platform Symphony HIGH 7.1
CVE-2018-1702

IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) at…

Mitigation only
Fix from $1,950 2018-09-28
Data Quality Suite CRITICAL 9.8
CVE-2018-17411

An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.

No fix yet
Fix from $2,300 2018-09-26
Javamelody CRITICAL 9.8
CVE-2018-15531EPSS 28%

JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.

Fix: 1.74.0+
Fix from $2,300 2018-09-26
Datapower Gateway HIGH 7.1
CVE-2018-1669

IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as we…

Fix: after 7.7.1.2
Fix from $1,950 2018-09-25
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1588

IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Inject…

Fix: after 6.0.6
Fix from $1,950 2018-09-25
Rational Engineering Lifecycle Manager HIGH 7.1
CVE-2018-1607

IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when …

Fix: after 6.0.6
Fix from $1,950 2018-09-25
Messaging Gateway HIGH 8.8
CVE-2018-12243

The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML …

Fix: 10.6.6+
Fix from $1,950 2018-09-19
Tika HIGH 7.5
CVE-2018-11761EPSS 10%

In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln…

Fix: after 1.18
Fix from $1,950 2018-09-19