Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2020-26709
py-xml v1.0 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a cra…
Py Xml
Mitigation only
HIGH 7.5
CVE-2020-26710
easy-parse v0.1.1 was discovered to contain a XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via …
Easy Parse
Mitigation only
HIGH 7.5
CVE-2023-3113
An unauthenticated XML external entity injection (XXE) vulnerability exists in LXCA's Common Information Model (CIM) server that could result in read…
Xclarity Administrator
4.0.0+
HIGH 7.5
CVE-2023-3276
A vulnerability, which was classified as problematic, has been found in Dromara HuTool up to 5.8.19. Affected by this issue is the function readBySax…
Hutool
after 5.8.19
CRITICAL 9.1
CVE-2023-24470
Potential XML External Entity Injection in ArcSight Logger versions prior to 7.3.0.
Arcsight Logger
7.3.0+
MEDIUM 5.5
CVE-2023-29498
Improper restriction of XML external entity reference (XXE) vulnerability exists in FRENIC RHC Loader v1.1.0.3 and earlier. If a user opens a special…
Frenic Rhc Loader
after 1.1.0.3
HIGH 7.5
CVE-2023-34411
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an X…
Xml Library
0.8.14+
MEDIUM 6.5
CVE-2023-32706
On Splunk Enterprise versions below 9.0.5, 8.2.11, and 8.1.14, an unauthenticated attacker can send specially-crafted messages to the XML parser with…
Splunk
8.1.14 / 8.2.11+
HIGH 7.1
CVE-2022-41221
The client in OpenText Archive Center Administration through 21.2 allows XXE attacks. Authenticated users of the OpenText Archive Center Administrati…
Archive Center Administration
after 21.2
HIGH 8.8
CVE-2023-2806
A vulnerability classified as problematic was found in Weaver e-cology up to 9.0. Affected by this vulnerability is the function RequestInfoByXml of …
E Cology
No fix yet
MEDIUM 5.5
CVE-2023-2161
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that
could cause unauthorized read access to the file system wh…
Opc Factory Server
3.63+
MEDIUM 6.3
CVE-2023-27554
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attack…
Websphere Application Server
8.5.5.24 / 9.0.5.16+
HIGH 7.5
CVE-2023-27527
Shinseiyo Sogo Soft (7.9A) and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitra…
Shinseiyo Sogo Soft
after 7.9a
MEDIUM 5.5
CVE-2022-45876
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase
11.7.5+
HIGH 8.1
CVE-2023-28008
HCL Workload Automation 9.4, 9.5, and 10.1 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…
Workload Automation
Mitigation only
HIGH 8.1
CVE-2023-28009
HCL Workload Automation is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
Workload Automation
Mitigation only
MEDIUM 6.5
CVE-2023-26057
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to the Configuration Dashboard page. Input validation and a proper X…
Netact
Mitigation only
MEDIUM 6.5
CVE-2023-26058
An XXE issue was discovered in Nokia NetAct before 22 FP2211 via an XML document to a Performance Manager page. Input validation and a proper XML par…
Netact
Mitigation only
MEDIUM 5.5
CVE-2023-27652
An issue found in Ego Studio SuperClean v.1.1.9 and v.1.1.5 allows an attacker to gain privileges cause a denial of service via the update_info field…
Super Clean
No fix yet
HIGH 7.5
CVE-2022-38840EPSS 10%
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file…
Man Eam 0003
No fix yet
MEDIUM 5.5
CVE-2023-26263
All versions of Talend Data Catalog before 8.0-20230110 are potentially vulnerable to XML External Entity (XXE) attacks in the /MIMBWebServices/licen…
Data Catalog
8.0-20230110+
MEDIUM 5.5
CVE-2023-26264
All versions of Talend Data Catalog before 8.0-20220907 are potentially vulnerable to XML External Entity (XXE) attacks in the license parsing code.
Data Catalog
8.0-20220907+
MEDIUM 5.9
CVE-2023-28828
A vulnerability has been identified in Polarion ALM (All versions < V22R2). The application contains a XML External Entity Injection (XXE) vulnerabil…
Polarion Alm
2304.0+
MEDIUM 5.5
CVE-2023-25955
National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a spec…
National Land Numerical Information Data Conversion Tool
Mitigation only
MEDIUM 6.5
CVE-2023-28340
Zoho ManageEngine Applications Manager through 16320 allows the admin user to conduct an XXE attack.
Manageengine Applications Manager
16.3+
HIGH 7.1
CVE-2023-27876
IBM TRIRIGA 4.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnera…
Tririga Application Platform
Patch available
MEDIUM 6.0
CVE-2023-20030
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access…
Identity Services Engine
3.2+
MEDIUM 6.5
CVE-2022-43941
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis ser…
Vantara Pentaho Business Analytics Server
9.3.0.2+
HIGH 7.5
CVE-2023-28680
Jenkins Crap4J Plugin 0.9 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Crap4j
after 0.9
HIGH 8.2
CVE-2023-28681
Jenkins Visual Studio Code Metrics Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Visual Studio Code Metrics
after 1.7