Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Dataease HIGH 7.5
CVE-2024-46985

DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the …

Fix: 2.10.1+
Fix from $1,950 2024-09-23
Reference Validator CRITICAL 9.8
CVE-2024-46984

The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile lo…

Fix: 2.5.1+
Fix from $2,300 2024-09-19
Winsure CRITICAL 9.8
CVE-2024-7098

Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure…

Fix: 4.6.2+
Fix from $2,300 2024-09-16
Endpoint Manager HIGH 8.2
CVE-2024-37397EPSS 59%

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot…

Fix: 2022+
Fix from $1,950 2024-09-12
Spectrum HIGH 8.8
CVE-2023-37233

Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.

Fix: 4.6_hf14+
Fix from $1,950 2024-09-10
Unclassified HIGH 8.6
CVE-2024-45294

The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Int…

Mitigation only
Fix from $1,950 2024-09-06
Libexpat HIGH 7.5
CVE-2024-45490

An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.

Fix: 2.6.3+
Fix from $1,950 2024-08-30
Phpspreadsheet MEDIUM 6.5
CVE-2024-45048

PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows…

Fix: 1.29.1 / 2.2.1+
Fix from $1,600 2024-08-28
Unclassified HIGH 8.8
CVE-2024-22218

XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submi…

Mitigation only
Fix from $1,950 2024-08-15
Avalanche HIGH 7.5
CVE-2024-38653EPSS 92%

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Mitigation only
Fix from $1,950 2024-08-14
Journyx HIGH 7.5
CVE-2024-6893EPSS 33%

The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attack…

No fix yet
Fix from $1,950 2024-08-08
Akana Api CRITICAL 9.8
CVE-2024-3930

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

Fix: 2024.1.0+
Fix from $2,300 2024-07-30
Drill HIGH 8.8
CVE-2023-48362

XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…

Fix: 1.21.2+
Fix from $1,950 2024-07-24
Unclassified MEDIUM 5.9
CVE-2024-6961

RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL docu…

Mitigation only
Fix from $1,600 2024-07-21
Unclassified MEDIUM 6.5
CVE-2024-5625

Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization Ex…

Mitigation only
Fix from $1,600 2024-07-18
Engineering Requirements Management Doors HIGH 8.2
CVE-2023-50304

IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d…

Mitigation only
Fix from $1,950 2024-07-18
Unclassified HIGH 7.5
CVE-2024-38374

The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Befo…

Patch available
Fix from $1,950 2024-06-28
Unclassified HIGH 7.5
CVE-2021-47621

ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.

Patch available
Fix from $1,950 2024-06-21
Unclassified HIGH 7.2
CVE-2023-49110

When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmit…

Mitigation only
Fix from $1,950 2024-06-20
Commerce CRITICAL 9.8
CVE-2024-34102 KEVEPSS 100%

Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX…

Fix: 1.5.0+
Fix from $2,300 2024-06-13
Ebookmeta HIGH 7.5
CVE-2024-36827

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive inf…

Fix: 1.2.8+
Fix from $1,950 2024-06-07
Ebookmeta CRITICAL 9.1
CVE-2024-37388

An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive informat…

Fix: 4.9.1+
Fix from $2,300 2024-06-07
Doors Next HIGH 8.2
CVE-2023-45192

IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…

Mitigation only
Fix from $1,950 2024-06-06
Imanager CRITICAL 9.8
CVE-2024-3969

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML…

Fix: 3.2.6+
Fix from $2,300 2024-05-28
Telerik Reporting MEDIUM 6.5
CVE-2024-4357

An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege atta…

Fix: 10.1.24.514+
Fix from $1,600 2024-05-15
Imanager CRITICAL 9.8
CVE-2024-3486

XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code executi…

Fix: 3.2.6+
Fix from $2,300 2024-05-15
Sharepoint Server HIGH 7.5
CVE-2024-30043EPSS 55%

Microsoft SharePoint Server Information Disclosure Vulnerability

Fix: 16.0.17328.20292+
Fix from $1,950 2024-05-14
Unclassified HIGH 8.1
CVE-2024-34345

The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were pos…

Patch available
Fix from $1,950 2024-05-14
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51605

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03
Saia Pg5 Controls Suite MEDIUM 6.5
CVE-2023-51600

Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …

Mitigation only
Fix from $1,600 2024-05-03