Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2022-29801 A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9). The application con… Teamcenter 12.4.0.13 / 13.0.0.9+ Fix from $1,9502022-05-20 HIGH 8.8 CVE-2022-30971 Jenkins Storable Configs Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Storable Configs after 1.0 Fix from $1,9502022-05-17 HIGH 7.5 CVE-2021-27777 XML External Entity (XXE) injection vulnerabilities occur when poorly configured XML parsers process user supplied input without sufficient validatio… Unica 12.1.1+ Fix from $1,9502022-05-12 CRITICAL 9.1 CVE-2021-42646 XML External Entity (XXE) vulnerability in the file based service provider creation feature of the Management Console in WSO2 API Manager 2.6.0, 3.0.… Api Manager Patch available Fix from $2,3002022-05-11 CRITICAL 9.1 CVE-2022-22774 The DOM XML parser and SAX XML parser components of TIBCO Software Inc.'s TIBCO Managed File Transfer Command Center, TIBCO Managed File Transfer Com… Managed File Transfer Command Center 8.3.2 / 8.4.2+ Fix from $2,3002022-05-10 CRITICAL 9.8 CVE-2021-23792 The package com.twelvemonkeys.imageio:imageio-metadata before 3.7.1 are vulnerable to XML External Entity (XXE) Injection due to an insecurely initia… Twelvemonkeys 3.7.1+ Fix from $2,3002022-05-06 CRITICAL 9.8 CVE-2022-28890 A vulnerability in the RDF/XML parser of Apache Jena allows an attacker to cause an external DTD to be retrieved. This issue affects Apache Jena vers… Jena Mitigation only Fix from $2,3002022-05-05 MEDIUM 6.5 CVE-2022-29943 Talend Administration Center has a vulnerability that allows an authenticated user to use XML External Entity (XXE) processing to achieve read access… Administration Center Mitigation only Fix from $1,6002022-05-04 HIGH 7.4 CVE-2022-20780EPSS 11% Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM… Enterprise Nfv Infrastructure Software 4.7.1+ Fix from $1,9502022-05-04 MEDIUM 5.5 CVE-2022-1331 In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific p… Dmars 2.1.10.24+ Fix from $1,6002022-05-03 HIGH 8.8 CVE-2022-21949 A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entiti… Open Build Service 2.10.13+ Fix from $1,9502022-05-03 HIGH 7.5 CVE-2022-29265 Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration. The Standard Content … Nifi after 1.16.0 Fix from $1,9502022-04-30 CRITICAL 9.8 CVE-2022-24449 Solar appScreener through 3.10.4, when a valid license is not present, allows XXE and SSRF attacks via a crafted XML document. Solar Appscreener after 3.10.4 Fix from $2,3002022-04-28 CRITICAL 9.8 CVE-2022-0272 Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0. Detekt 1.20.0+ Fix from $2,3002022-04-21 MEDIUM 5.3 CVE-2021-43990 The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an exter… Roboguide after 9.40083.00.05 Fix from $1,6002022-04-20 MEDIUM 5.5 CVE-2022-0221 A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a mali… Scadapack Workbench after 6.6.8a Fix from $1,6002022-04-13 CRITICAL 9.8 CVE-2022-28219EPSS 97% Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution. Manageengine Adaudit Plus after 6.0 Fix from $2,3002022-04-05 MEDIUM 5.5 CVE-2022-1018 When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe ca… Connected Components Workbench after 12.0 Fix from $1,6002022-04-01 HIGH 7.2 CVE-2021-33208 The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration f… Mashzone Nextgen after 10.7 Fix from $1,9502022-03-30 CRITICAL 9.8 CVE-2021-43142 An XML External Entity (XXE) vulnerability exists in wuta jox 1.16 in the readObject method in JOXSAXBeanInput. Jox after 1.16 Fix from $2,3002022-03-30 HIGH 8.1 CVE-2022-28154 Jenkins Coverage/Complexity Scatter Plot Plugin 1.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Coverage\/complexity Scatter Plot after 1.1.1 Fix from $1,9502022-03-29 HIGH 8.1 CVE-2022-28155 Jenkins Pipeline: Phoenix AutoTest Plugin 1.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Pipeline\ after 1.3 Fix from $1,9502022-03-29 HIGH 8.1 CVE-2022-28140 Jenkins Flaky Test Handler Plugin 1.2.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Flaky Test Handler after 1.2.1 Fix from $1,9502022-03-29 HIGH 7.5 CVE-2021-44477 GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that cou… Toolboxst 07.09.07c+ Fix from $1,9502022-03-25 CRITICAL 9.8 CVE-2021-43090 An XML External Entity (XXE) vulnerability exists in soa-model before 1.6.4 in the WSDLParser function. Soa Model 1.6.4+ Fix from $2,3002022-03-25 HIGH 7.2 CVE-2021-42194 The wechat_return function in /controller/Index.php of EyouCms V1.5.4-UTF8-SP3 passes the user's input directly into the simplexml_ load_ String func… Eyoucms No fix yet Fix from $1,9502022-03-20 MEDIUM 5.5 CVE-2022-27193 CVRF-CSAF-Converter before 1.0.0-rc2 resolves XML External Entities (XXE). This leads to the inclusion of arbitrary (local) file content into the gen… Cvrf Csaf Converter Mitigation only Fix from $1,6002022-03-15 MEDIUM 6.5 CVE-2022-26661 An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tr… Debian Linux 5.0.12 / 5.0.46+ Fix from $1,6002022-03-10 MEDIUM 6.5 CVE-2022-22835EPSS 15% An issue was discovered in OverIT Geocall before version 8.0. An authenticated user who has the Test Trasformazione XSL functionality enabled can exp… Geocall 8.0+ Fix from $1,6002022-03-10 CRITICAL 9.1 CVE-2022-22795 Signiant - Manager+Agents XML External Entity (XXE) - Extract internal files of the affected machine An attacker can read all the system files, the p… Manager\+agents 13.5+ Fix from $2,3002022-03-10