Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Unclassified HIGH 8.8
CVE-2024-52596

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it'…

Patch available
Fix from $1,950 2024-12-02
Unclassified HIGH 8.3
CVE-2024-52806

SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse,…

Patch available
Fix from $1,950 2024-12-02
Insight Remote Support HIGH 7.5
CVE-2024-53674EPSS 47%

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Insight Remote Support HIGH 7.5
CVE-2024-53675EPSS 84%

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Insight Remote Support HIGH 7.5
CVE-2024-11622

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

Fix: 7.14.0.629+
Fix from $1,950 2024-11-26
Imanager CRITICAL 9.8
CVE-2023-24466

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

Fix: 3.2.6+
Fix from $2,300 2024-11-22
Worldserver MEDIUM 6.5
CVE-2024-50848

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensit…

Mitigation only
Fix from $1,600 2024-11-18
Phpspreadsheet HIGH 7.5
CVE-2024-48917

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks.…

Fix: 1.29.4 / 2.1.3+
Fix from $1,950 2024-11-18
Phpspreadsheet HIGH 7.5
CVE-2024-47873

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. H…

Fix: 1.29.4 / 2.1.3+
Fix from $1,950 2024-11-18
Catalyst Sd Wan Manager MEDIUM 6.5
CVE-2020-26066

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to in…

Mitigation only
Fix from $1,600 2024-11-18
Engineering Lifecycle Optimization Engineering Insights HIGH 8.2
CVE-2024-39726

IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro…

Mitigation only
Fix from $1,950 2024-11-15
Catalyst Sd Wan Manager MEDIUM 6.4
CVE-2021-1483

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to in…

Mitigation only
Fix from $1,600 2024-11-15
Dompdf CRITICAL 9.8
CVE-2021-3902

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and dese…

Fix: 2.0.0+
Fix from $2,300 2024-11-15
Pan Os MEDIUM 6.5
CVE-2024-5919

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate…

Fix: 10.1.10 / 10.2.5+
Fix from $1,600 2024-11-14
Unclassified CRITICAL 9.2
CVE-2024-10218

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational I…

No fix yet
Fix from $2,300 2024-11-12
Unclassified HIGH 8.6
CVE-2024-52007

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components…

Patch available
Fix from $1,950 2024-11-08
Manageengine Sharepoint Manager Plus HIGH 8.1
CVE-2024-10839

Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management opt…

Mitigation only
Fix from $1,950 2024-11-08
Identity Services Engine MEDIUM 6.5
CVE-2024-20531

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of a…

Mitigation only
Fix from $1,600 2024-11-06
Unclassified CRITICAL 9.8
CVE-2024-51132

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via …

Mitigation only
Fix from $2,300 2024-11-05
Websphere Application Server MEDIUM 5.5
CVE-2024-45086

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged us…

Fix: 8.5.5.27 / 9.0.5.22+
Fix from $1,600 2024-11-04
Openimaj CRITICAL 9.8
CVE-2024-51136

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code…

No fix yet
Fix from $2,300 2024-11-04
Royal Elementor Addons HIGH 7.2
CVE-2024-50442

Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.Th…

Fix: 1.3.981+
Fix from $1,950 2024-10-28
Application Automation Tools HIGH 8.0
CVE-2024-4184

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects …

Fix: after 24.1.0
Fix from $1,950 2024-10-16
Application Automation Tools HIGH 8.0
CVE-2024-4189

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects …

Fix: after 24.1.0
Fix from $1,950 2024-10-16
Application Automation Tools HIGH 8.0
CVE-2024-4690

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects …

Fix: after 24.1.0
Fix from $1,950 2024-10-16
Websphere Application Server MEDIUM 5.5
CVE-2024-45072

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged us…

Fix: after 9.0.5.21
Fix from $1,600 2024-10-16
Peoplesoft Enterprise Peopletools HIGH 8.8
CVE-2024-21255

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected …

Mitigation only
Fix from $1,950 2024-10-15
Unclassified MEDIUM 6.3
CVE-2024-8602

When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML …

Mitigation only
Fix from $1,600 2024-10-14
Formatting Objects Processor HIGH 7.5
CVE-2024-28168

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: …

Mitigation only
Fix from $1,950 2024-10-09
Phpspreadsheet HIGH 7.5
CVE-2024-45293

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XL…

Fix: 1.29.1 / 2.1.1+
Fix from $1,950 2024-10-07