Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Unclassified MEDIUM 6.8
CVE-2025-25036

Improper Restriction of XML External Entity Reference vulnerability in Jalios JPlatform allows XML Injection.This issue affects all versions of JPlat…

Mitigation only
Fix from $1,600 2025-03-21
Unclassified MEDIUM 6.3
CVE-2025-2365

A vulnerability, which was classified as problematic, has been found in crmeb_java up to 1.3.4. Affected by this issue is the function webHook of the…

Mitigation only
Fix from $1,600 2025-03-17
Unclassified MEDIUM 5.5
CVE-2025-27136

LocalS3 is an Amazon S3 mock service for testing and local development. Prior to version 1.21, the LocalS3 service's bucket creation endpoint is vuln…

Patch available
Fix from $1,600 2025-03-10
Aspera Shares HIGH 7.1
CVE-2025-0162

IBM Aspera Shares 1.9.9 through 1.10.0 PL7 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenti…

Fix: 1.10.0+
Fix from $1,950 2025-03-07
Unclassified CRITICAL 9.8
CVE-2023-38693

Lucee Server (or simply Lucee) is a dynamic, Java based, tag and scripting language used for rapid web application development. The Lucee REST endpoi…

Mitigation only
Fix from $2,300 2025-03-05
Openpages With Watson HIGH 7.1
CVE-2024-49781

IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote…

Fix: 8.3.0.3 / 9.0.0.5+
Fix from $1,950 2025-02-20
Cognos Controller HIGH 8.2
CVE-2023-47160

IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when p…

Fix: 11.0.1.4+
Fix from $1,950 2025-02-19
Yimioa MEDIUM 6.3
CVE-2025-1225

A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03. This issue affects the function extract of the file c-…

Fix: 2024-07-04+
Fix from $1,600 2025-02-12
Entirex HIGH 7.1
CVE-2024-54171

IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. An authenticated attacker could exploit thi…

Mitigation only
Fix from $1,950 2025-02-06
Cognos Analytics HIGH 7.1
CVE-2024-49352

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injec…

Fix: 11.2.4 / 12.0.4+
Fix from $1,950 2025-02-05
Unclassified HIGH 8.6
CVE-2024-52807

The HL7 FHIR IG publisher is a tool to take a set of inputs and create a standard FHIR IG. Prior to version 1.7.4, XSLT transforms performed by vario…

Patch available
Fix from $1,950 2025-01-24
Ambari HIGH 7.5
CVE-2025-23195

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie project, allowing an attacker to inject malicious XML entities. This vulnerab…

Fix: 2.7.9+
Fix from $1,950 2025-01-21
Unclassified HIGH 7.8
CVE-2024-12476

CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation inte…

Mitigation only
Fix from $1,950 2025-01-17
Unclassified MEDIUM 5.5
CVE-2024-12298

We found a vulnerability Improper Restriction of XML External Entity Reference (CWE-611) in NB-series NX-Designer. Attackers may be able to abuse thi…

Mitigation only
Fix from $1,600 2025-01-14
G5dfr Firmware HIGH 7.5
CVE-2024-46602

An issue was discovered in Elspec G5 digital fault recorder version 1.2.1.12 and earlier. An XML External Entity (XXE) vulnerability may allow an att…

Fix: 1.2.2.19+
Fix from $1,950 2025-01-07
G5dfr Firmware HIGH 7.5
CVE-2024-46603

An XML External Entity (XXE) vulnerability in Elspec Engineering G5 Digital Fault Recorder Firmware v1.2.1.12 allows attackers to cause a Denial of S…

Fix: 1.2.2.19+
Fix from $1,950 2025-01-07
Gocd HIGH 7.2
CVE-2024-56322

GoCD is a continuous deliver server. GoCD versions 16.7.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse a hidden/unused configuration rep…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Gocd HIGH 7.1
CVE-2024-56324

GoCD is a continuous deliver server. GoCD versions prior to 24.4.0 can allow GoCD "group admins" to abuse ability to edit the raw XML configuration f…

Fix: 24.5.0+
Fix from $1,950 2025-01-03
Libxml2 CRITICAL 9.1
CVE-2024-40896

In libxml2 2.11 before 2.11.9, 2.12 before 2.12.9, and 2.13 before 2.13.3, the SAX parser can produce events for external entities even if custom SAX…

Fix: 2.11.9 / 2.12.9+
Fix from $2,300 2024-12-23
Teamcity HIGH 7.1
CVE-2024-56356

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

Fix: 2024.12+
Fix from $1,950 2024-12-20
Unclassified CRITICAL 9.8
CVE-2024-55081

An XML External Entity (XXE) injection vulnerability in the component /datagrip/upload of Chat2DB v0.3.5 allows attackers to execute arbitrary code v…

Mitigation only
Fix from $2,300 2024-12-19
Unclassified MEDIUM 5.3
CVE-2021-22501

Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation.  The vuln…

Mitigation only
Fix from $1,600 2024-12-19
Unclassified HIGH 8.6
CVE-2024-55887

Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable t…

Mitigation only
Fix from $1,950 2024-12-13
Unclassified CRITICAL 9.8
CVE-2024-55875

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vuln…

Patch available
Fix from $2,300 2024-12-12
Sharepoint Server MEDIUM 6.5
CVE-2024-49064

Microsoft SharePoint Information Disclosure Vulnerability

No fix yet
Fix from $1,600 2024-12-12
Acrobat MEDIUM 6.3
CVE-2024-49535

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an Improper Restriction of X…

Fix: 20.005.30748 / 24.001.30225+
Fix from $1,600 2024-12-10
Unclassified MEDIUM 5.1
CVE-2024-54005

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V1…

Mitigation only
Fix from $1,600 2024-12-10
Unclassified MEDIUM 5.5
CVE-2024-49704

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V1…

Mitigation only
Fix from $1,600 2024-12-10
Unclassified MEDIUM 5.3
CVE-2024-47582

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion att…

Mitigation only
Fix from $1,600 2024-12-10
Unclassified CRITICAL 9.8
CVE-2024-46455

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

Mitigation only
Fix from $2,300 2024-12-09