Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2020-26709 py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a cra… Py Xml Mitigation only Fix from $1,9502023-06-29 HIGH 7.5 CVE-2020-26710 easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via … Easy Parse Mitigation only Fix from $1,9502023-06-29 HIGH 7.5 CVE-2023-3113 An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read… Xclarity Administrator 4.0.0+ Fix from $1,9502023-06-26 HIGH 7.5 CVE-2023-3276 A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax… Hutool after 5.8.19 Fix from $1,9502023-06-15 CRITICAL 9.1 CVE-2023-24470 Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0. Arcsight Logger 7.3.0+ Fix from $2,3002023-06-13 MEDIUM 5.5 CVE-2023-29498 Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a special… Frenic Rhc Loader after 1.1.0.3 Fix from $1,6002023-06-13 HIGH 7.5 CVE-2023-34411 The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an X… Xml Library 0.8.14+ Fix from $1,9502023-06-05 MEDIUM 6.5 CVE-2023-32706 On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with… Splunk 8.1.14 / 8.2.11+ Fix from $1,6002023-06-01 HIGH 7.1 CVE-2022-41221 The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administrati… Archive Center Administration after 21.2 Fix from $1,9502023-05-24 HIGH 8.8 CVE-2023-2806 A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of … E Cology No fix yet Fix from $1,9502023-05-19 MEDIUM 5.5 CVE-2023-2161 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system wh… Opc Factory Server 3.63+ Fix from $1,6002023-05-16 MEDIUM 6.3 CVE-2023-27554 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack… Websphere Application Server 8.5.5.24 / 9.0.5.16+ Fix from $1,6002023-05-11 HIGH 7.5 CVE-2023-27527 Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitra… Shinseiyo Sogo Soft after 7.9a Fix from $1,9502023-05-10 MEDIUM 5.5 CVE-2022-45876 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase 11.7.5+ Fix from $1,6002023-04-26 HIGH 8.1 CVE-2023-28008 HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke… Workload Automation Mitigation only Fix from $1,9502023-04-26 HIGH 8.1 CVE-2023-28009 HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this… Workload Automation Mitigation only Fix from $1,9502023-04-26 MEDIUM 6.5 CVE-2023-26057 An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper X… Netact Mitigation only Fix from $1,6002023-04-25 MEDIUM 6.5 CVE-2023-26058 An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML par… Netact Mitigation only Fix from $1,6002023-04-25 MEDIUM 5.5 CVE-2023-27652 An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field… Super Clean No fix yet Fix from $1,6002023-04-20 HIGH 7.5 CVE-2022-38840EPSS 10% cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file… Man Eam 0003 No fix yet Fix from $1,9502023-04-16 MEDIUM 5.5 CVE-2023-26263 All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/licen… Data Catalog 8.0-20230110+ Fix from $1,6002023-04-13 MEDIUM 5.5 CVE-2023-26264 All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code. Data Catalog 8.0-20220907+ Fix from $1,6002023-04-13 MEDIUM 5.9 CVE-2023-28828 A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerabil… Polarion Alm 2304.0+ Fix from $1,6002023-04-11 MEDIUM 5.5 CVE-2023-25955 National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a spec… National Land Numerical Information Data Conversion Tool Mitigation only Fix from $1,6002023-04-11 MEDIUM 6.5 CVE-2023-28340 Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack. Manageengine Applications Manager 16.3+ Fix from $1,6002023-04-11 HIGH 7.1 CVE-2023-27876 IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera… Tririga Application Platform Patch available Fix from $1,9502023-04-07 MEDIUM 6.0 CVE-2023-20030 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access… Identity Services Engine 3.2+ Fix from $1,6002023-04-05 MEDIUM 6.5 CVE-2022-43941 Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis ser… Vantara Pentaho Business Analytics Server 9.3.0.2+ Fix from $1,6002023-04-03 HIGH 7.5 CVE-2023-28680 Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Crap4j after 0.9 Fix from $1,9502023-04-02 HIGH 8.2 CVE-2023-28681 Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Visual Studio Code Metrics after 1.7 Fix from $1,9502023-04-02