Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 5.3 CVE-2023-42445 Gradle is a build tool with a focus on build automation and support for multi-language development. In some cases, when Gradle parses XML files, reso… Gradle 7.6.3 / 8.4.0+ Fix from $1,6002023-10-06 MEDIUM 5.5 CVE-2023-42132 FD Application Apr. 2022 Edition (Version 9.01) and earlier improperly restricts XML external entity references (XXE). By processing a specially craf… Fd Application after 9.01 Fix from $1,6002023-10-02 HIGH 7.5 CVE-2023-38343 An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity referen… Endpoint Manager 2022+ Fix from $1,9502023-09-21 HIGH 7.4 CVE-2023-3892 Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking … Assistant Mitigation only Fix from $1,9502023-09-19 HIGH 8.8 CVE-2023-41933 Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not configure its XML parser to prevent XML external entity (XXE) attac… Job Configuration History after 1229.v3039470161a_d Fix from $1,9502023-09-06 MEDIUM 6.5 CVE-2023-41932 Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and earlier does not restrict 'timestamp' query parameters in multiple endpoints, allowi… Job Configuration History after 1227.v7a_79fc4dc01f Fix from $1,6002023-09-06 CRITICAL 9.1 CVE-2023-35892 IBM Financial Transaction Manager for SWIFT Services 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A… Financial Transaction Manager Mitigation only Fix from $2,3002023-09-05 HIGH 7.5 CVE-2023-40239 Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.… C2132 Firmware Mitigation only Fix from $1,9502023-09-01 CRITICAL 9.8 CVE-2023-41034 Eclipse Leshan is a device management server and client Java implementation. In affected versions DDFFileParser` and `DefaultDDFFileValidator` (and s… Leshan 1.5.0+ Fix from $2,3002023-08-31 MEDIUM 5.5 CVE-2023-24620 An issue was discovered in Esoteric YamlBeans through 1.15. A crafted YAML document is able perform am XML Entity Expansion attack against YamlBeans … Yamlbeans after 1.15 Fix from $1,6002023-08-25 CRITICAL 9.8 CVE-2022-48565 An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist fil… Python 3.6.13 / 3.7.10+ Fix from $2,3002023-08-22 HIGH 8.2 CVE-2022-46751 Improper Restriction of XML External Entity Reference, XML Injection (aka Blind XPath Injection) vulnerability in Apache Software Foundation Apache I… Ivy 2.5.2+ Fix from $1,9502023-08-21 MEDIUM 6.1 CVE-2023-0871 XXE injection in /rtc/post/ endpoint in OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2 on multiple platforms is vulnerable to XML external e… Horizon 32.0.2 / 2020.1.38+ Fix from $1,6002023-08-11 HIGH 7.5 CVE-2023-3823 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configura… PHP 8.0.30 / 8.1.22+ Fix from $1,9502023-08-11 CRITICAL 9.8 CVE-2023-32567 Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236 Avalanche 6.4.1+ Fix from $2,3002023-08-10 MEDIUM 6.5 CVE-2023-35389 Microsoft Dynamics 365 On-Premises Remote Code Execution Vulnerability Dynamics 365 9.0.47.08 / 9.1.18.22+ Fix from $1,6002023-08-08 HIGH 8.1 CVE-2020-26064 A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to informa… Catalyst Sd Wan Manager Mitigation only Fix from $1,9502023-08-04 HIGH 8.8 CVE-2023-37497 The Unica application exposes an API which accepts arbitrary XML input. By manipulating the given XML, an authenticated attacker with certain rights … Unica 11.1.0.6 / 12.1.1+ Fix from $1,9502023-08-03 MEDIUM 6.5 CVE-2023-30951 The Foundry Magritte plugin rest-source was found to be vulnerable to an an XML external Entity attack (XXE). Magritte Rest Source Bundle 7.210.0+ Fix from $1,6002023-08-03 CRITICAL 9.1 CVE-2023-37364 In WS-Inc J WBEM Server 4.7.4 before 4.7.5, the CIM-XML protocol adapter does not disable entity resolution. This allows context-dependent attackers … J Wbem 4.7.5+ Fix from $2,3002023-08-03 CRITICAL 10.0 CVE-2023-38490 Kirby is a content management system. A vulnerability in versions prior to 3.5.8.3, 3.6.6.3, 3.7.5.2, 3.8.4.1, and 3.9.6 only affects Kirby sites tha… Kirby 3.5.8.3 / 3.6.6.3+ Fix from $2,3002023-07-27 MEDIUM 5.5 CVE-2023-32639 Applicant Programme Ver.7.06 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbit… Applicant Programme after 7.06 Fix from $1,6002023-07-25 MEDIUM 5.5 CVE-2023-32635 XBRL data create application version 7.0 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XBR… Xbrl Data Create after 7.0 Fix from $1,6002023-07-19 CRITICAL 9.8 CVE-2023-20918 In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused deputy with no additional execut… Android Patch available Fix from $2,3002023-07-13 MEDIUM 6.5 CVE-2023-37942 Jenkins External Monitor Job Type Plugin 206.v9a_94ff0b_4a_10 and earlier does not configure its XML parser to prevent XML external entity (XXE) atta… External Monitor Job Type after 206.v9a_94ff0b_4a_10 Fix from $1,6002023-07-12 MEDIUM 5.5 CVE-2023-37200 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a proje… Ecostruxure Opc Ua Server Expert 2.01+ Fix from $1,6002023-07-12 HIGH 7.5 CVE-2020-26708 requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code v… Requests Xml Mitigation only Fix from $1,9502023-06-29 HIGH 7.5 CVE-2020-26709 py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a cra… Py Xml Mitigation only Fix from $1,9502023-06-29 HIGH 7.5 CVE-2020-26710 easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via … Easy Parse Mitigation only Fix from $1,9502023-06-29 HIGH 7.5 CVE-2023-3113 An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read… Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26