Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.2
CVE-2023-28682
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Performance Publisher
after 8.09
HIGH 8.2
CVE-2023-28683
Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Phabricator Differential
after 2.1.5
MEDIUM 6.5
CVE-2023-28684
Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Remote Jobs View
after 0.0.3
MEDIUM 5.4
CVE-2022-43473EPSS 20%
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM…
Manageengine Opmanager
12.6+
HIGH 7.1
CVE-2022-36969EPSS 14%
This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.…
Aveva Edge
2020.2.00.40+
CRITICAL 9.8
CVE-2023-28150
An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX fi…
Jodf
1.1.110+
CRITICAL 9.8
CVE-2023-28151
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a…
Jspreadsheet
1.1.110+
CRITICAL 9.8
CVE-2023-28152
An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX f…
Jword
1.1.110+
HIGH 7.1
CVE-2023-28685
Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Absint A3
after 1.1.0
MEDIUM 5.5
CVE-2022-41696
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase Automation Base
11.7.5+
MEDIUM 5.5
CVE-2022-43512
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase Automation Base
11.7.5+
MEDIUM 5.5
CVE-2022-45121
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase Automation Base
11.7.5+
MEDIUM 5.5
CVE-2022-45468
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase Automation Base
11.7.5+
MEDIUM 5.5
CVE-2022-46300
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
Vbase Automation Base
11.7.5+
CRITICAL 9.8
CVE-2018-25082
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipula…
Wechat Sdk Python
0.5.5+
HIGH 8.8
CVE-2023-27874
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul…
Aspera Faspex
after 4.4.2
HIGH 7.5
CVE-2023-1288
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
Enovia Live Collaboration
Mitigation only
HIGH 7.5
CVE-2023-27476
OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content mo…
Owslib
0.28.1+
HIGH 7.7
CVE-2023-27480
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ…
Xwiki
13.10.11 / 14.4.7+
MEDIUM 5.3
CVE-2023-20052EPSS 7%
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:
A vulnerability in the DMG file parser of ClamAV vers…
Secure Endpoint
1.20.2 / 1.21.1+
MEDIUM 6.5
CVE-2023-26043
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML …
Geonode
4.0.3+
CRITICAL 9.8
CVE-2023-24189
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/comm…
Urule
No fix yet
HIGH 8.8
CVE-2023-20855
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche…
Vrealize Automation
8.11.1+
MEDIUM 6.5
CVE-2023-26267
php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silent…
Php Saml Sp
1.1.1 / 2.1.1+
CRITICAL 9.8
CVE-2015-10082
A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c o…
Libplist
Patch available
HIGH 7.8
CVE-2016-15026
A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulat…
Dd Plist
1.18+
CRITICAL 9.8
CVE-2014-125087
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The m…
Java Xmlbuilder
1.2+
HIGH 7.5
CVE-2021-33950
An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function.
Openkm
Patch available
CRITICAL 9.1
CVE-2022-39954
An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, Fort…
Fortinac
7.2.0 / 9.4.2+
HIGH 8.1
CVE-2023-23926
APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml proce…
Awesome Procedures On Cyper
5.5.0+