Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.4
CVE-2023-22377
Improper restriction of XML external entity reference (XXE) vulnerability exists in tsClinical Define.xml Generator all versions (v1.0.0 to v1.4.0) a…
Tsclinical Define.xml Generator
1.1.1+
HIGH 7.8
CVE-2023-24187
An XML External Entity (XXE) vulnerability in ureport v2.2.9 allows attackers to execute arbitrary code via uploading a crafted XML file to /ureport/…
Ureport
No fix yet
HIGH 7.5
CVE-2023-22832
The ExtractCCDAAttributes Processor in Apache NiFi 1.2.0 through 1.19.1 does not restrict XML External Entity references.
Flow configurations that i…
Nifi
after 1.19.1
HIGH 8.8
CVE-2023-24323
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
Mojoportal
No fix yet
HIGH 7.8
CVE-2022-45588
All versions before R2022-09 of Talend's Remote Engine Gen 2 are potentially vulnerable to XML External Entity (XXE) type of attacks. Users should do…
Remote Engine Gen 2
Mitigation only
CRITICAL 9.1
CVE-2022-38389
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
CRITICAL 9.1
CVE-2022-22486
IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tivoli Workload Scheduler
Mitigation only
CRITICAL 9.8
CVE-2022-47873
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
Keos
Mitigation only
MEDIUM 5.5
CVE-2023-22322
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a spec…
Cx Motion Pro
1.4.6.014+
CRITICAL 9.8
CVE-2023-24443
Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Testcomplete Support
after 2.8.1
CRITICAL 9.8
CVE-2023-24429
Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitatio…
Semantic Versioning
1.15+
CRITICAL 9.8
CVE-2023-24430
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Semantic Versioning
1.15+
CRITICAL 9.8
CVE-2023-24441
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Mstest
after 1.0.0
HIGH 8.1
CVE-2023-21862
Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: XML Security component). The supported version tha…
Web Services Manager
Patch available
HIGH 7.5
CVE-2023-22624
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
Manageengine Exchange Reporter Plus
5.7+
HIGH 7.5
CVE-2023-23595
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "m…
Device Registration Portal
No fix yet
CRITICAL 9.8
CVE-2021-4311
A vulnerability classified as problematic was found in Talend Open Studio for MDM. This vulnerability affects unknown code of the component XML Handl…
Open Studio
20230102_1935+
CRITICAL 9.8
CVE-2015-10029
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0. This vulnerability affects unknown code of the file simplexrd/…
Simplexrd
3.1.1+
CRITICAL 9.8
CVE-2016-15011
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1. Affected by this vulnerability is the function checkSignResponse …
Dssp
1.3.2+
CRITICAL 9.8
CVE-2020-36641
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0. This vulnerability affects the function ResponseParser of the fil…
Axmlrpc
after 1.12.1
CRITICAL 9.8
CVE-2020-36640
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function Tran…
Webservice Connector
1.3.1+
CRITICAL 9.8
CVE-2017-20151
A vulnerability classified as problematic was found in iText RUPS. This vulnerability affects unknown code of the file src/main/java/com/itextpdf/rup…
Rups
2017-08-01+
CRITICAL 9.8
CVE-2021-4295
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30. This vulnerability affects the function vocabularyValidat…
Code Validator Api
1.0.31+
HIGH 7.5
CVE-2022-41967
Dragonfly is a Java runtime dependency management library. Dragonfly v0.3.0-SNAPSHOT does not configure DocumentBuilderFactory to prevent XML externa…
Dragonfly
Patch available
CRITICAL 9.8
CVE-2022-4607
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0. It has been rated as problematic. This issue affects some unknown …
Ogc Web Feature Service
5.2.1+
HIGH 8.8
CVE-2022-47514
An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request for…
Xml Rpc.net
2.5.0+
HIGH 8.8
CVE-2022-25628
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
Symantec Identity Governance And Administration
Mitigation only
MEDIUM 5.5
CVE-2022-37911
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS. A successful exploit could allo…
Sd Wan
6.5.4.22 / 8.6.0.17+
CRITICAL 9.8
CVE-2022-46682
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Plot
2.1.12+
MEDIUM 5.5
CVE-2022-46827
In JetBrains IntelliJ IDEA before 2022.3 an XXE attack leading to SSRF via requests to custom plugin repositories was possible.
Intellij Idea
2022.3+