Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 6.5 CVE-2023-51601 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51602 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51604 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 HIGH 7.5 CVE-2023-51591 Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attack… Viewpower Mitigation only Fix from $1,9502024-05-03 HIGH 8.2 CVE-2023-44412EPSS 84% D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose… D View 8 Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2023-42035 Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attac… Myconnection Server Mitigation only Fix from $1,6002024-05-03 HIGH 7.5 CVE-2023-40506 LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl… Simple Editor Mitigation only Fix from $1,9502024-05-03 HIGH 7.5 CVE-2023-40507 LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl… Simple Editor Mitigation only Fix from $1,9502024-05-03 HIGH 7.5 CVE-2023-40503 LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to discl… Simple Editor Mitigation only Fix from $1,9502024-05-03 MEDIUM 6.5 CVE-2023-39472 Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote a… Ignition 8.1.32+ Fix from $1,6002024-05-03 HIGH 7.1 CVE-2024-29010 The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially resulting in the disclosure … Mitigation only Fix from $1,9502024-05-01 HIGH 7.0 CVE-2024-22354 IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vulnerable to an XML External En… Websphere Application Server 8.5.5.26 / 9.0.5.20+ Fix from $1,9502024-04-17 CRITICAL 9.8 CVE-2024-21082 Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: XML Services). Supported versions that are affected are 7.0.0.0.0 a… Bi Publisher Mitigation only Fix from $2,3002024-04-16 MEDIUM 6.3 CVE-2023-49234 An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to access local server files an… Mitigation only Fix from $1,6002024-03-29 MEDIUM 6.5 CVE-2024-25971 Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high privileged attacker could poten… Powerprotect Data Manager 19.16+ Fix from $1,6002024-03-28 HIGH 8.1 CVE-2024-31139 In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector Teamcity 2024.03+ Fix from $1,9502024-03-28 HIGH 8.8 CVE-2024-2826 A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects unknown code of the file /urepo… Easyadmin after 2024-03-15 Fix from $1,9502024-03-22 MEDIUM 5.8 CVE-2024-28039 Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a remote unauthenticated attacker … Mitigation only Fix from $1,6002024-03-18 HIGH 8.2 CVE-2024-27266 IBM Maximo Application Suite 7.6.1.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could… Maximo Application Suite Patch available Fix from $1,9502024-03-14 HIGH 7.7 CVE-2023-50168 Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. Pega Platform 8.8.5+ Fix from $1,9502024-03-14 HIGH 7.5 CVE-2024-28198 OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manually manipulating http requests… Openolat 18.1.6+ Fix from $1,9502024-03-11 HIGH 8.2 CVE-2023-25926 IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when proce… Security Guardium Key Lifecycle Manager 4.1.1.7+ Fix from $1,9502024-02-29 MEDIUM 6.5 CVE-2023-50380 XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More De… Ambari 2.7.8+ Fix from $1,6002024-02-27 MEDIUM 5.5 CVE-2024-25129 The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser used by the CodeQL CLI to read… Codeql Cli 2.16.3+ Fix from $1,6002024-02-22 HIGH 8.7 CVE-2024-25606 XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before update 4, 7.3 before update 12,… Digital Experience Platform 7.2 / 7.4.3.8+ Fix from $1,9502024-02-20 HIGH 8.3 CVE-2024-22024EPSS 95% An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate… Connect Secure Mitigation only Fix from $1,9502024-02-13 HIGH 7.5 CVE-2024-24743 SAP NetWeaver AS Java (CAF - Guided Procedures) - version 7.50, allows an unauthenticated attacker to submit a malicious request with a crafted XML f… Netweaver Application Server Java Mitigation only Fix from $1,9502024-02-13 MEDIUM 6.5 CVE-2023-52239 The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport. Magic Xpi Integration Platform No fix yet Fix from $1,6002024-02-06 HIGH 7.1 CVE-2023-32327 IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security Verify Access Docker 10.0.0.0 … Security Verify Access after 10.0.6.1 Fix from $1,9502024-02-03 HIGH 7.5 CVE-2024-1167 When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. Movitools Motionstudio Mitigation only Fix from $1,9502024-02-01