Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Ua .net Legacy HIGH 8.2
CVE-2018-12585

An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

Fix: after 1.3.343
Fix from $1,950 2018-09-14
Windows 10 HIGH 8.8
CVE-2018-8420EPSS 49%

A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Executio…

Patch available
Fix from $1,950 2018-09-13
Html Form Entry CRITICAL 9.8
CVE-2018-16521

An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

Patch available
Fix from $2,300 2018-09-05
Pdf Xchange Editor HIGH 7.5
CVE-2018-16303

PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a…

Fix: after 7.0.326.1
Fix from $1,950 2018-09-01
Project Portfolio Management HIGH 7.5
CVE-2018-13823

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allo…

Fix: after 14.3
Fix from $1,950 2018-08-30
Project Portfolio Management CRITICAL 9.1
CVE-2018-13826

An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allo…

Fix: after 14.3
Fix from $2,300 2018-08-30
Episerver HIGH 7.5
CVE-2017-17762

XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XM…

Fix: after 7
Fix from $1,950 2018-08-29
Cayenne HIGH 8.1
CVE-2018-11758

This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shippe…

Fix: after 3.1.0
Fix from $1,950 2018-08-22
Jabref CRITICAL 10.0
CVE-2018-1000652

JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential d…

Fix: after 4.3.1
Fix from $2,300 2018-08-20
Stroom CRITICAL 10.0
CVE-2018-1000651

Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of …

Fix: 5.4.5+
Fix from $2,300 2018-08-20
Rdf4j CRITICAL 10.0
CVE-2018-1000644

Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in…

Fix: 2.4.0+
Fix from $2,300 2018-08-20
Latexdraw CRITICAL 9.6
CVE-2018-1000639

LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server…

Fix: after 3.3.9
Fix from $2,300 2018-08-20
Bittorrent Client CRITICAL 9.8
CVE-2018-13417EPSS 21%

In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack…

No fix yet
Fix from $2,300 2018-08-13
Media Server CRITICAL 9.8
CVE-2018-13415EPSS 32%

In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.…

No fix yet
Fix from $2,300 2018-08-13
Emc Data Protection Advisor HIGH 8.1
CVE-2018-11048

Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XM…

Mitigation only
Fix from $1,950 2018-08-10
Activematrix Businessworks HIGH 7.5
CVE-2018-12408

The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO…

Fix: after 5.13.0
Fix from $1,950 2018-08-08
Airwave HIGH 8.8
CVE-2016-8526EPSS 10%

Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to…

Fix: 8.2.3.1+
Fix from $1,950 2018-08-06
Ocsinventory Ng CRITICAL 9.1
CVE-2018-14473

OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sendi…

No fix yet
Fix from $2,300 2018-08-04
Universal Media Server CRITICAL 9.8
CVE-2018-13416EPSS 20%

In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) at…

No fix yet
Fix from $2,300 2018-08-03
Intellij Idea HIGH 7.5
CVE-2017-8316

IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code…

Fix: 2017.2.2+
Fix from $1,950 2018-08-03
Business Planning And Consolidation HIGH 8.1
CVE-2017-16349

An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e…

Mitigation only
Fix from $1,950 2018-08-02
Focalscope CRITICAL 9.4
CVE-2018-3881

An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a spe…

No fix yet
Fix from $2,300 2018-08-01
Camel CRITICAL 9.8
CVE-2018-8027EPSS 6%

Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor.

Fix: after 2.20.3
Fix from $2,300 2018-07-31
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7464

It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi…

Mitigation only
Fix from $2,300 2018-07-27
Decision Manager MEDIUM 6.5
CVE-2017-7545

It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a…

Patch available
Fix from $1,600 2018-07-26
Acselerator Architect CRITICAL 9.8
CVE-2018-10600

SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieva…

Fix: after 2.2.24.0
Fix from $2,300 2018-07-24
Cas Server HIGH 8.8
CVE-2014-2296

XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when …

Fix: 3.4.12.1 / 3.5.2.1+
Fix from $1,950 2018-07-20
Common CRITICAL 9.8
CVE-2018-14065

XMLReader.php in PHPOffice Common before 0.2.9 allows XXE.

Fix: 0.2.9+
Fix from $2,300 2018-07-15
Epubcheck HIGH 7.8
CVE-2016-9487

EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a s…

Mitigation only
Fix from $1,950 2018-07-13
Fortify Software Security Center CRITICAL 9.8
CVE-2018-12463EPSS 14%

An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to…

No fix yet
Fix from $2,300 2018-07-12