Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.4 CVE-2023-22377 Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) a… Tsclinical Define.xml Generator 1.1.1+ Fix from $1,9502023-02-15 HIGH 7.8 CVE-2023-24187 An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/… Ureport No fix yet Fix from $1,9502023-02-14 HIGH 7.5 CVE-2023-22832 The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references. Flow configurations that i… Nifi after 1.19.1 Fix from $1,9502023-02-10 HIGH 8.8 CVE-2023-24323 Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability. Mojoportal No fix yet Fix from $1,9502023-02-09 HIGH 7.8 CVE-2022-45588 All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should do… Remote Engine Gen 2 Mitigation only Fix from $1,9502023-02-03 CRITICAL 9.1 CVE-2022-38389 IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Tivoli Workload Scheduler Mitigation only Fix from $2,3002023-02-03 CRITICAL 9.1 CVE-2022-22486 IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Tivoli Workload Scheduler Mitigation only Fix from $2,3002023-02-03 CRITICAL 9.8 CVE-2022-47873 Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote). Keos Mitigation only Fix from $2,3002023-01-31 MEDIUM 5.5 CVE-2023-22322 Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a spec… Cx Motion Pro 1.4.6.014+ Fix from $1,6002023-01-30 CRITICAL 9.8 CVE-2023-24443 Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Testcomplete Support after 2.8.1 Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24429 Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio… Semantic Versioning 1.15+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24430 Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Semantic Versioning 1.15+ Fix from $2,3002023-01-26 CRITICAL 9.8 CVE-2023-24441 Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Mstest after 1.0.0 Fix from $2,3002023-01-26 HIGH 8.1 CVE-2023-21862 Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component). The supported version tha… Web Services Manager Patch available Fix from $1,9502023-01-18 HIGH 7.5 CVE-2023-22624 Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks. Manageengine Exchange Reporter Plus 5.7+ Fix from $1,9502023-01-17 HIGH 7.5 CVE-2023-23595 BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "m… Device Registration Portal No fix yet Fix from $1,9502023-01-15 CRITICAL 9.8 CVE-2021-4311 A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handl… Open Studio 20230102_1935+ Fix from $2,3002023-01-09 CRITICAL 9.8 CVE-2015-10029 A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/… Simplexrd 3.1.1+ Fix from $2,3002023-01-07 CRITICAL 9.8 CVE-2016-15011 A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse … Dssp 1.3.2+ Fix from $2,3002023-01-06 CRITICAL 9.8 CVE-2020-36641 A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the fil… Axmlrpc after 1.12.1 Fix from $2,3002023-01-05 CRITICAL 9.8 CVE-2020-36640 A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function Tran… Webservice Connector 1.3.1+ Fix from $2,3002023-01-05 CRITICAL 9.8 CVE-2017-20151 A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rup… Rups 2017-08-01+ Fix from $2,3002022-12-30 CRITICAL 9.8 CVE-2021-4295 A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidat… Code Validator Api 1.0.31+ Fix from $2,3002022-12-29 HIGH 7.5 CVE-2022-41967 Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML externa… Dragonfly Patch available Fix from $1,9502022-12-28 CRITICAL 9.8 CVE-2022-4607 A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown … Ogc Web Feature Service 5.2.1+ Fix from $2,3002022-12-18 HIGH 8.8 CVE-2022-47514 An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request for… Xml Rpc.net 2.5.0+ Fix from $1,9502022-12-18 HIGH 8.8 CVE-2022-25628 An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 Symantec Identity Governance And Administration Mitigation only Fix from $1,9502022-12-16 MEDIUM 5.5 CVE-2022-37911 Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allo… Sd Wan 6.5.4.22 / 8.6.0.17+ Fix from $1,6002022-12-12 CRITICAL 9.8 CVE-2022-46682 Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Plot 2.1.12+ Fix from $2,3002022-12-12 MEDIUM 5.5 CVE-2022-46827 In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible. Intellij Idea 2022.3+ Fix from $1,6002022-12-08