Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Onos CRITICAL 9.8
CVE-2018-1000614

ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosp…

Fix: after 1.13.1
Fix from $2,300 2018-07-09
Onos CRITICAL 9.8
CVE-2018-1000616

ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onospr…

Fix: after 1.13.1
Fix from $2,300 2018-07-09
Wechat Pay HIGH 7.5
CVE-2018-13439

WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.

No fix yet
Fix from $1,950 2018-07-08
Filenet Content Manager HIGH 7.1
CVE-2018-1542

IBM FileNet Content Manager, IBM Content Foundation, and IBM Case Foundation Administration Console for Content Platform Engine (ACCE) 5.2.1 and 5.5.…

Patch available
Fix from $1,950 2018-07-06
Solr MEDIUM 5.5
CVE-2018-8026EPSS 9%

This vulnerability in Apache Solr 6.0.0 to 6.6.4 and 7.0.0 to 7.3.1 relates to an XML external entity expansion (XXE) in Solr config files (currency.…

Fix: after 7.3.1
Fix from $1,600 2018-07-05
Powermedia Xms CRITICAL 9.1
CVE-2018-11640

XML External Entity (XXE) vulnerability in the web service in Dialogic PowerMedia XMS before 3.5 SU2 allows remote attackers to read arbitrary files …

Fix: after 3.5
Fix from $2,300 2018-07-03
Somachine Basic HIGH 7.5
CVE-2018-7783

Schneider Electric SoMachine Basic prior to v1.6 SP1 suffers from an XML External Entity (XXE) vulnerability using the DTD parameter entities techniq…

Fix: after 1.6
Fix from $1,950 2018-07-03
Jboss Enterprise Application Platform CRITICAL 9.8
CVE-2017-7465

It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw …

Mitigation only
Fix from $2,300 2018-06-27
Loboevolution HIGH 7.8
CVE-2018-1000540

LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the X…

Fix: 0.99.3+
Fix from $1,950 2018-06-26
Netbeans Mmd Plugin HIGH 7.8
CVE-2018-1000542

netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information di…

No fix yet
Fix from $1,950 2018-06-26
Triplea HIGH 7.8
CVE-2018-1000546

Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information di…

Fix: after 1.9.0.0.10291
Fix from $1,950 2018-06-26
Umlet HIGH 7.8
CVE-2018-1000548

Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of…

Fix: 14.3+
Fix from $1,950 2018-06-26
News Articles HIGH 7.5
CVE-2018-1000515

ventrian News-Articles version NewsArticles.00.09.11 contains a XML External Entity (XXE) vulnerability in News-Articles/API/MetaWebLog/Handler.ashx.…

No fix yet
Fix from $1,950 2018-06-26
Automatedlogic Webctrl HIGH 7.5
CVE-2018-8819

An XXE issue was discovered in Automated Logic Corporation (ALC) WebCTRL Versions 6.0, 6.1 and 6.5. An unauthenticated attacker could enter malicious…

No fix yet
Fix from $1,950 2018-06-14
Administrator MEDIUM 6.5
CVE-2018-5433

The TIBCO Administrator server component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, and TIBCO Administrator - Enterprise Edit…

Fix: after 5.10.0
Fix from $1,600 2018-06-13
Runtime Agent MEDIUM 6.5
CVE-2018-5434

The TIBCO Designer component of TIBCO Software Inc.'s TIBCO Runtime Agent, and TIBCO Runtime Agent for z/Linux contains vulnerabilities wherein a mal…

Fix: after 5.10.0
Fix from $1,600 2018-06-13
Flamingo CRITICAL 9.8
CVE-2017-3206

The Java implementation of AMF3 deserializers used by Flamingo amf-serializer by Exadel, version 2.2.0, allows external entity references (XXEs) from…

No fix yet
Fix from $2,300 2018-06-11
Weborb For Java CRITICAL 9.8
CVE-2017-3208

The Java implementation of AMF3 deserializers used by WebORB for Java by Midnight Coders, version 5.1.1.0, allows external entity references (XXEs) f…

No fix yet
Fix from $2,300 2018-06-11
Common Catalog MEDIUM 6.5
CVE-2018-6670

External Entity Attack vulnerability in the ePO extension in McAfee Common UI (CUI) 2.0.2 allows remote authenticated users to view confidential info…

Fix: 2.0.3+
Fix from $1,600 2018-06-07
Rational Rhapsody Design Manager HIGH 7.1
CVE-2018-1456

IBM Rhapsody DM 5.0 through 5.0.2 and 6.0 through 6.0.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem…

Patch available
Fix from $1,950 2018-06-06
Black Duck Hub MEDIUM 6.5
CVE-2018-1000198

A XML external entity processing vulnerability exists in Jenkins Black Duck Hub Plugin 3.1.0 and older in PostBuildScanDescriptor.java that allows at…

Fix: after 3.1.0
Fix from $1,600 2018-06-05
Searchblox CRITICAL 9.8
CVE-2018-11586EPSS 15%

XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files or conduct…

No fix yet
Fix from $2,300 2018-06-05
Mds Pulsenet HIGH 7.5
CVE-2018-10613EPSS 18%

Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS Pulse…

Fix: after 3.2.1
Fix from $1,950 2018-06-04
Xenmobile Server CRITICAL 9.8
CVE-2018-10653EPSS 7%

There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

No fix yet
Fix from $2,300 2018-05-23
Nifi CRITICAL 9.8
CVE-2018-1309

Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The f…

Fix: 1.6.0+
Fix from $2,300 2018-05-23
Solr MEDIUM 5.5
CVE-2018-8010

This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.x…

Fix: after 7.3.0
Fix from $1,600 2018-05-21
Coldfusion HIGH 7.5
CVE-2018-4942

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processin…

Mitigation only
Fix from $1,950 2018-05-19
User Import Export HIGH 8.1
CVE-2017-2815

An exploitable XML entity injection vulnerability exists in OpenFire User Import Export Plugin 2.6.0. A specially crafted web request can cause the r…

Mitigation only
Fix from $1,950 2018-05-15
Modbuspal MEDIUM 5.5
CVE-2018-10832EPSS 6%

ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files…

No fix yet
Fix from $1,600 2018-05-11
Spring Data Rest HIGH 7.5
CVE-2018-1259EPSS 5%

Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a p…

Fix: after 3.0.6
Fix from $1,950 2018-05-11