Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.2 CVE-2023-28682 Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Performance Publisher after 8.09 Fix from $1,9502023-04-02 HIGH 8.2 CVE-2023-28683 Jenkins Phabricator Differential Plugin 2.1.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Phabricator Differential after 2.1.5 Fix from $1,9502023-04-02 MEDIUM 6.5 CVE-2023-28684 Jenkins remote-jobs-view-plugin Plugin 0.0.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Remote Jobs View after 0.0.3 Fix from $1,6002023-04-02 MEDIUM 5.4 CVE-2022-43473EPSS 20% A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XM… Manageengine Opmanager 12.6+ Fix from $1,6002023-03-30 HIGH 7.1 CVE-2022-36969EPSS 14% This vulnerability allows remote attackers to disclose sensitive information on affected installations of AVEVA Edge 2020 SP2 Patch 0(4201.2111.1802.… Aveva Edge 2020.2.00.40+ Fix from $1,9502023-03-29 CRITICAL 9.8 CVE-2023-28150 An issue was discovered in Independentsoft JODF before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX fi… Jodf 1.1.110+ Fix from $2,3002023-03-24 CRITICAL 9.8 CVE-2023-28151 An issue was discovered in Independentsoft JSpreadsheet before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a… Jspreadsheet 1.1.110+ Fix from $2,3002023-03-24 CRITICAL 9.8 CVE-2023-28152 An issue was discovered in Independentsoft JWord before 1.1.110. The API is prone to XML external entity (XXE) injection via a remote DTD in a DOCX f… Jword 1.1.110+ Fix from $2,3002023-03-24 HIGH 7.1 CVE-2023-28685 Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Absint A3 after 1.1.0 Fix from $1,9502023-03-22 MEDIUM 5.5 CVE-2022-41696 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase Automation Base 11.7.5+ Fix from $1,6002023-03-21 MEDIUM 5.5 CVE-2022-43512 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase Automation Base 11.7.5+ Fix from $1,6002023-03-21 MEDIUM 5.5 CVE-2022-45121 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase Automation Base 11.7.5+ Fix from $1,6002023-03-21 MEDIUM 5.5 CVE-2022-45468 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase Automation Base 11.7.5+ Fix from $1,6002023-03-21 MEDIUM 5.5 CVE-2022-46300 Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. Vbase Automation Base 11.7.5+ Fix from $1,6002023-03-21 CRITICAL 9.8 CVE-2018-25082 A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical. This issue affects the function validate/to_xml. The manipula… Wechat Sdk Python 0.5.5+ Fix from $2,3002023-03-21 HIGH 8.8 CVE-2023-27874 IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote authenticated attacker coul… Aspera Faspex after 4.4.2 Fix from $1,9502023-03-21 HIGH 7.5 CVE-2023-1288 An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server. Enovia Live Collaboration Mitigation only Fix from $1,9502023-03-09 HIGH 7.5 CVE-2023-27476 OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content mo… Owslib 0.28.1+ Fix from $1,9502023-03-08 HIGH 7.7 CVE-2023-27480 XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with edit righ… Xwiki 13.10.11 / 14.4.7+ Fix from $1,9502023-03-07 MEDIUM 5.3 CVE-2023-20052EPSS 7% On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the DMG file parser of ClamAV vers… Secure Endpoint 1.20.2 / 1.21.1+ Fix from $1,6002023-03-01 MEDIUM 6.5 CVE-2023-26043 GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. GeoNode is vulnerable to an XML … Geonode 4.0.3+ Fix from $1,6002023-02-27 CRITICAL 9.8 CVE-2023-24189 An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/comm… Urule No fix yet Fix from $2,3002023-02-24 HIGH 8.8 CVE-2023-20855 VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability. A malicious actor, with non-administrative access to vRealize Orche… Vrealize Automation 8.11.1+ Fix from $1,9502023-02-22 MEDIUM 6.5 CVE-2023-26267 php-saml-sp before 1.1.1 and 2.x before 2.1.1 allows reading arbitrary files as the webserver user because resolving XML external entities was silent… Php Saml Sp 1.1.1 / 2.1.1+ Fix from $1,6002023-02-21 CRITICAL 9.8 CVE-2015-10082 A vulnerability classified as problematic has been found in UIKit0 libplist 1.12. This affects the function plist_from_xml of the file src/xplist.c o… Libplist Patch available Fix from $2,3002023-02-21 HIGH 7.8 CVE-2016-15026 A vulnerability was found in 3breadt dd-plist 1.17 and classified as problematic. Affected by this issue is some unknown functionality. The manipulat… Dd Plist 1.18+ Fix from $1,9502023-02-20 CRITICAL 9.8 CVE-2014-125087 A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The m… Java Xmlbuilder 1.2+ Fix from $2,3002023-02-19 HIGH 7.5 CVE-2021-33950 An issue discovered in OpenKM v6.3.10 allows attackers to obtain sensitive information via the XMLTextExtractor function. Openkm Patch available Fix from $1,9502023-02-17 CRITICAL 9.1 CVE-2022-39954 An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, Fort… Fortinac 7.2.0 / 9.4.2+ Fix from $2,3002023-02-16 HIGH 8.1 CVE-2023-23926 APOC (Awesome Procedures on Cypher) is an add-on library for Neo4j. An XML External Entity (XXE) vulnerability found in the apoc.import.graphml proce… Awesome Procedures On Cyper 5.5.0+ Fix from $1,9502023-02-16