Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
.net Core HIGH 7.5
CVE-2018-0765EPSS 8%

A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerab…

Patch available
Fix from $1,950 2018-05-09
Authentication Manager HIGH 7.1
CVE-2018-1247EPSS 16%

RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allo…

Fix: after 8.3
Fix from $1,950 2018-05-08
Emc Smis CRITICAL 9.8
CVE-2018-1183

In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, D…

Fix: 4.3.0.1522077968 / 8.4.0.6+
Fix from $2,300 2018-04-30
Uimaj MEDIUM 6.5
CVE-2017-15691EPSS 9%

In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui…

Fix: 2.2.2 / 2.4.0+
Fix from $1,600 2018-04-26
Rational Clearcase CRITICAL 9.1
CVE-2014-0931

Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java…

Fix: after 8.0.1.3
Fix from $2,300 2018-04-20
Rational Clearquest HIGH 7.1
CVE-2014-0950

Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) Cle…

Fix: after 8.0.1.3
Fix from $1,950 2018-04-20
Management Console MEDIUM 6.5
CVE-2018-10175

Digital Guardian Management Console 7.1.2.0015 has an XXE issue.

No fix yet
Fix from $1,600 2018-04-20
Ide HIGH 7.5
CVE-2017-8315

Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit t…

No fix yet
Fix from $1,950 2018-04-20
Management Console HIGH 8.0
CVE-2017-6323

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference…

Fix: 8.1+
Fix from $1,950 2018-04-16
Solr HIGH 7.5
CVE-2018-1308EPSS 21%

This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` …

Fix: after 7.2.1
Fix from $1,950 2018-04-09
Datapower Gateway HIGH 7.1
CVE-2018-1421

IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing…

Fix: after 7.6.0.5
Fix from $1,950 2018-04-04
Wiremock CRITICAL 9.1
CVE-2018-9116

An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentia…

Fix: 2.16.0+
Fix from $2,300 2018-03-29
Connections MEDIUM 6.5
CVE-2015-7461

XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cau…

Fix: after 3.0.1.1
Fix from $1,600 2018-03-20
Opencart CRITICAL 9.8
CVE-2014-3990EPSS 7%

The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger…

Fix: after 1.5.6.4
Fix from $2,300 2018-03-20
Sap Business Process Automation HIGH 8.8
CVE-2018-2401

SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML…

Mitigation only
Fix from $1,950 2018-03-14
Spacewalk HIGH 7.5
CVE-2018-1077

Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server.

Mitigation only
Fix from $1,950 2018-03-14
I\, Librarian CRITICAL 10.0
CVE-2018-1000124

I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s…

Fix: after 4.8
Fix from $2,300 2018-03-13
Textpattern HIGH 7.5
CVE-2018-1000090

textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the…

No fix yet
Fix from $1,950 2018-03-13
Debian Linux MEDIUM 5.5
CVE-2018-1000069

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing da…

Fix: after 1.5.9
Fix from $1,600 2018-03-13
Infosphere Information Server MEDIUM 5.4
CVE-2016-0250

XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote …

Fix: 11.3.1.2+
Fix from $1,600 2018-03-12
Jive N MEDIUM 6.5
CVE-2018-5758

The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file…

No fix yet
Fix from $1,600 2018-03-12
Mps110 1 Firmware HIGH 8.8
CVE-2018-7230

A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professiona…

Fix: 3.29.67+
Fix from $1,950 2018-03-09
Identity Manager CRITICAL 9.1
CVE-2017-7426

The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to lea…

Fix: 4.6.1+
Fix from $2,300 2018-03-01
Mxgraph CRITICAL 9.8
CVE-2017-18197

In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (X…

Fix: after 3.7.5
Fix from $2,300 2018-02-24
Project And Portfolio Management Center CRITICAL 9.8
CVE-2018-6489

XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to …

Mitigation only
Fix from $2,300 2018-02-22
Financial Transaction Manager HIGH 7.1
CVE-2017-1758

IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3…

Patch available
Fix from $1,950 2018-02-21
Debian Linux CRITICAL 9.8
CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…

Fix: after 2.9.4
Fix from $2,300 2018-02-19
Aruba Clearpass Policy Manager HIGH 8.1
CVE-2017-5828

An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found.

Fix: 6.6.5+
Fix from $1,950 2018-02-15
Internet Graphics Server HIGH 7.5
CVE-2018-2392EPSS 41%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14
Internet Graphics Server HIGH 7.5
CVE-2018-2393EPSS 15%

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus…

Mitigation only
Fix from $1,950 2018-02-14