Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 6.5 CVE-2023-4554 Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Server Side Request Forgery, Prob… Appbuilder 23.2+ Fix from $1,6002024-01-29 MEDIUM 5.5 CVE-2024-21765 Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delive… Electronic Delivery Check System 11.0.0 / 13.0.0+ Fix from $1,6002024-01-24 MEDIUM 5.5 CVE-2024-21796 Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Su… Electronic Deliverables Creation Support Tool 1.0.4+ Fix from $1,6002024-01-24 MEDIUM 5.5 CVE-2024-22380 Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heise… Electronic Delivery Check System after 14.0.001.002 Fix from $1,6002024-01-24 MEDIUM 6.5 CVE-2024-23525 The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option of XML::Twig. Spreadsheet\ 0.30+ Fix from $1,6002024-01-18 HIGH 7.5 CVE-2023-45139 fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Injection (XXE) vulnerability which… Fonttools 4.43.0+ Fix from $1,9502024-01-10 MEDIUM 6.5 CVE-2023-6149 Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, which was missing a permission … Web Application Screening after 2.0.11 Fix from $1,6002024-01-09 MEDIUM 6.5 CVE-2023-6147 Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing … Policy Compliance after 1.0.5 Fix from $1,6002024-01-09 CRITICAL 9.8 CVE-2023-26999 An issue found in NetScout nGeniusOne v.6.3.4 allows a remote attacker to execute arbitrary code and cause a denial of service via a crafted file. Ngeniusone Mitigation only Fix from $2,3002024-01-09 CRITICAL 9.8 CVE-2023-52252 Unified Remote 3.13.0 allows remote attackers to execute arbitrary Lua code because of a wildcarded Access-Control-Allow-Origin for the Remote upload… Unified Remote No fix yet Fix from $2,3002023-12-30 CRITICAL 9.8 CVE-2023-46265 An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF). Avalanche after 6.4.1 Fix from $2,3002023-12-19 HIGH 7.5 CVE-2023-6280 An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the … Wps 4.0.0+ Fix from $1,9502023-12-19 HIGH 7.5 CVE-2023-6836 Multiple WSO2 products have been identified as vulnerable due to an XML External Entity (XXE) attack abuses a widely available but rarely used featur… Api Manager after 6.6.0 Fix from $1,9502023-12-15 HIGH 7.5 CVE-2023-6721 An XEE vulnerability has been found in Repox, which allows a remote attacker to interfere with the application's XML data processing in the fileuploa… Repox Mitigation only Fix from $1,9502023-12-13 HIGH 7.1 CVE-2023-6194 In Eclipse Memory Analyzer versions 0.7 to 1.14.0, report definition XML files are not filtered to prohibit document type definition (DTD) references… Memory Analyzer after 1.14.0 Fix from $1,9502023-12-11 CRITICAL 9.8 CVE-2023-49733 Improper Restriction of XML External Entity Reference vulnerability in Apache Cocoon.This issue affects Apache Cocoon: from 2.2.0 before 2.3.0. User… Cocoon 2.3.0+ Fix from $2,3002023-11-30 CRITICAL 9.8 CVE-2023-49656 Jenkins MATLAB Plugin 2.11.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Matlab 2.11.1+ Fix from $2,3002023-11-29 HIGH 7.5 CVE-2023-22274 Adobe RoboHelp Server versions 11.4 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that c… Robohelp Server after 11.4 Fix from $1,9502023-11-17 HIGH 7.5 CVE-2023-46590 A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external en… Siemens Opc Ua Modeling Editor 2.8+ Fix from $1,9502023-11-14 MEDIUM 5.0 CVE-2023-4218 In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to o… Eclipse Ide 3.13.2400 / 3.29.0+ Fix from $1,6002023-11-09 MEDIUM 5.5 CVE-2023-5136 An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulne… Topografix Data Plugin Mitigation only Fix from $1,6002023-11-08 MEDIUM 5.5 CVE-2023-46802 e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parse… E Tax after 3.0.10 Fix from $1,6002023-11-06 CRITICAL 9.8 CVE-2023-46502 An issue in openCRX v.5.2.2 allows a remote attacker to read internal files and execute server side request forgery attack via insecure DocumentBuild… Opencrx Patch available Fix from $2,3002023-10-30 MEDIUM 6.5 CVE-2022-34832 An issue was discovered in VERMEG AgileReporter 21.3. XXE can occur via an XML document to the Analysis component. Agile Reporter No fix yet Fix from $1,6002023-10-27 MEDIUM 6.5 CVE-2023-43067 Dell Unity prior to 5.3 contains an XML External Entity injection vulnerability. An XXE attack could potentially exploit this vulnerability disclosin… Unity Operating Environment 5.3.0.0.5.120+ Fix from $1,6002023-10-23 MEDIUM 5.5 CVE-2023-43624 CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vuln… Cx Designer after 3.740 Fix from $1,6002023-10-23 HIGH 7.5 CVE-2023-45727 KEV Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and e… Proself 1.09 / 1.66+ Fix from $1,9502023-10-18 CRITICAL 9.1 CVE-2022-32755 IBM Security Directory Server 6.4.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could … Security Directory Server Patch available Fix from $2,3002023-10-14 CRITICAL 9.8 CVE-2023-36419 Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability Azure Hdinsight Patch available Fix from $2,3002023-10-10 CRITICAL 9.8 CVE-2023-45612 In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXE Ktor 2.3.5+ Fix from $2,3002023-10-09