Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Itext HIGH 8.8
CVE-2017-9096EPSS 10%

The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML exter…

Fix: 5.5.12+
Fix from $1,950 2017-11-08
Activemq Apollo CRITICAL 9.8
CVE-2014-3579

XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…

Mitigation only
Fix from $2,300 2017-10-27
Activemq CRITICAL 9.8
CVE-2014-3600EPSS 10%

XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…

Mitigation only
Fix from $2,300 2017-10-27
Xml Rpc HIGH 7.8
CVE-2016-5002EPSS 8%

XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…

Mitigation only
Fix from $1,950 2017-10-27
Mura Cms MEDIUM 6.5
CVE-2017-15639EPSS 7%

tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.

Fix: after 6.1
Fix from $1,600 2017-10-19
Mediawiki CRITICAL 9.8
CVE-2014-9487

The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service…

Mitigation only
Fix from $2,300 2017-10-17
Solr CRITICAL 9.8
CVE-2017-12629EPSS 92%

Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…

Fix: after 7.0.1
Fix from $2,300 2017-10-14
Contrail MEDIUM 5.0
CVE-2017-10617

The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sy…

Fix: 2.21.4 / 3.0.3.4+
Fix from $1,600 2017-10-13
Umbraco Cms MEDIUM 5.5
CVE-2017-15280

XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server o…

Fix: after 7.7.2
Fix from $1,600 2017-10-12
Nifi MEDIUM 6.5
CVE-2017-12623

An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…

Mitigation only
Fix from $1,600 2017-10-10
Lansweeper CRITICAL 9.9
CVE-2017-13706

XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote au…

Fix: after 6.0.100.29
Fix from $2,300 2017-10-10
Roller CRITICAL 9.8
CVE-2014-0030EPSS 17%

The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

No fix yet
Fix from $2,300 2017-10-10
Document Sciences Xpression CRITICAL 9.8
CVE-2017-14759

OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone …

Fix: after 4.5
Fix from $2,300 2017-10-03
Opennlp CRITICAL 9.8
CVE-2017-12620

When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…

No fix yet
Fix from $2,300 2017-10-03
Tika HIGH 7.8
CVE-2016-4434

Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…

Mitigation only
Fix from $1,950 2017-09-30
Commons Jelly CRITICAL 9.8
CVE-2017-12621EPSS 9%

During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …

Fix: 1.0.1+
Fix from $2,300 2017-09-28
Documentum Administrator HIGH 8.8
CVE-2017-14526

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list th…

Mitigation only
Fix from $1,950 2017-09-28
Documentum Administrator HIGH 8.8
CVE-2017-14527

Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the conte…

No fix yet
Fix from $1,950 2017-09-28
Business Process Manager HIGH 8.1
CVE-2017-1527

IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attac…

Patch available
Fix from $1,950 2017-09-26
Dive Assistant MEDIUM 5.5
CVE-2017-8918

XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafte…

No fix yet
Fix from $1,600 2017-09-12
Single Sign On For Pivotal Cloud Foundry MEDIUM 6.5
CVE-2017-8040

In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attac…

Patch available
Fix from $1,600 2017-09-09
Diving Log MEDIUM 5.5
CVE-2017-9095

XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.

Fix: 6.0.9+
Fix from $1,600 2017-09-08
Socialminer HIGH 8.8
CVE-2017-12216

A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to…

Mitigation only
Fix from $1,950 2017-09-07
Pan Os CRITICAL 9.8
CVE-2017-9458

XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.…

Fix: after 6.1.17
Fix from $2,300 2017-09-07
Netweaver CRITICAL 9.8
CVE-2015-7241EPSS 13%

XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.

Fix: after 7.0
Fix from $2,300 2017-09-06
Qradar Network Security HIGH 8.1
CVE-2017-1458

IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…

Mitigation only
Fix from $1,950 2017-09-05
I Vu HIGH 7.3
CVE-2016-5795

An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and C…

Fix: after 6.5
Fix from $1,950 2017-08-31
Simatic Pcs7 HIGH 8.2
CVE-2017-12069

An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Am…

Fix: after 2017-03-21
Fix from $1,950 2017-08-30
Digital Editions HIGH 7.5
CVE-2017-11272EPSS 13%

Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.

Fix: after 4.5.5
Fix from $1,950 2017-08-11
Cxf HIGH 7.5
CVE-2016-8739EPSS 7%

The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apach…

Fix: after 3.0.11
Fix from $1,950 2017-08-10