Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Junit HIGH 8.3
CVE-2018-1000056

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p…

Fix: after 1.23
Fix from $1,950 2018-02-09
Ccm HIGH 8.3
CVE-2018-1000054

Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm…

Fix: after 3.1
Fix from $1,950 2018-02-09
Android Lint HIGH 8.3
CVE-2018-1000055

Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with …

Fix: after 2.5
Fix from $1,950 2018-02-09
Control Manager MEDIUM 6.5
CVE-2018-3600

A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose …

Patch available
Fix from $1,600 2018-02-09
Juddi HIGH 8.1
CVE-2018-1307

In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…

Fix: after 3.3.4
Fix from $1,950 2018-02-09
Wing HIGH 7.5
CVE-2018-5789

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML …

Fix: 5.8.6.9 / 5.9.1.3+
Fix from $1,950 2018-02-05
Fortify Audit Workbench CRITICAL 9.8
CVE-2018-6486

XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions…

Mitigation only
Fix from $2,300 2018-02-02
Fedora CRITICAL 9.8
CVE-2014-3005EPSS 5%

XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allow…

Patch available
Fix from $2,300 2018-02-01
Sugarcrm CRITICAL 9.8
CVE-2014-3244EPSS 5%

XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent…

Fix: 6.5.16+
Fix from $2,300 2018-02-01
Dsl Ac51 Firmware MEDIUM 6.5
CVE-2017-14699

Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U…

Patch available
Fix from $1,600 2018-01-29
Content Navigator HIGH 8.2
CVE-2018-1364

IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp…

Mitigation only
Fix from $1,950 2018-01-29
Pmd HIGH 8.8
CVE-2018-1000008

Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…

Fix: after 3.49
Fix from $1,950 2018-01-23
Checkstyle HIGH 8.8
CVE-2018-1000009

Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with u…

Fix: after 3.49
Fix from $1,950 2018-01-23
Dry HIGH 8.8
CVE-2018-1000010

Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…

Fix: after 2.49
Fix from $1,950 2018-01-23
Findbugs HIGH 8.8
CVE-2018-1000011

Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…

Fix: after 4.71
Fix from $1,950 2018-01-23
Warnings HIGH 8.8
CVE-2018-1000012

Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…

Fix: after 4.64
Fix from $1,950 2018-01-23
Webex Meetings Server MEDIUM 5.3
CVE-2018-0108

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML Exter…

Mitigation only
Fix from $1,600 2018-01-18
Rational Quality Manager MEDIUM 6.5
CVE-2016-0219

XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.…

Mitigation only
Fix from $1,600 2018-01-16
Security Key Lifecycle Manager HIGH 8.1
CVE-2017-1666

IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…

Patch available
Fix from $1,950 2018-01-09
Xmlbundle HIGH 7.5
CVE-2017-1000477

XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.

No fix yet
Fix from $1,950 2018-01-03
Commsy HIGH 8.8
CVE-2017-1000496

Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execut…

Mitigation only
Fix from $1,950 2018-01-03
Pepperminty Wiki CRITICAL 9.8
CVE-2017-1000497

Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code executi…

Mitigation only
Fix from $2,300 2018-01-03
Androidsvg HIGH 7.8
CVE-2017-1000498

AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

Mitigation only
Fix from $1,950 2018-01-03
Play Framework CRITICAL 9.8
CVE-2014-3630

XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attac…

Mitigation only
Fix from $2,300 2017-12-29
Conserus Image Repository CRITICAL 9.8
CVE-2017-14101

A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesso…

Mitigation only
Fix from $2,300 2017-12-15
Coldfusion HIGH 7.5
CVE-2017-11286EPSS 8%

Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update…

Patch available
Fix from $1,950 2017-12-01
Restlet HIGH 7.5
CVE-2017-14868

Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP…

Fix: 2.3.11+
Fix from $1,950 2017-11-30
Restlet HIGH 7.5
CVE-2017-14949

Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, be…

Fix: 2.3.12+
Fix from $1,950 2017-11-30
Solr CRITICAL 9.1
CVE-2017-1000190

SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.

Fix: after 2.7.1
Fix from $2,300 2017-11-17
Security Access Manager 9.0 Firmware HIGH 8.1
CVE-2017-1477

IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…

Mitigation only
Fix from $1,950 2017-11-13