Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
CRITICAL 9.1 CVE-2022-25312 An XML external entity (XXE) injection vulnerability was discovered in the Any23 RDFa XSLTStylesheet extractor and is known to affect Any23 versions … Any23 2.7+ Fix from $2,3002022-03-05 CRITICAL 9.8 CVE-2022-0839 Improper Restriction of XML External Entity Reference in GitHub repository liquibase/liquibase prior to 4.8.0. Liquibase 4.8.0+ Fix from $2,3002022-03-04 CRITICAL 9.8 CVE-2022-0265 Improper Restriction of XML External Entity Reference in GitHub repository hazelcast/hazelcast in 5.1-BETA-1. Hazelcast Patch available Fix from $2,3002022-03-03 CRITICAL 9.8 CVE-2022-23640 Excel-Streaming-Reader is an easy-to-use implementation of a streaming Excel reader using Apache POI. Prior to xlsx-streamer 2.1.0, the XML parser th… Excel Streaming Reader 2.1.0+ Fix from $2,3002022-03-02 CRITICAL 9.8 CVE-2022-24340 In JetBrains TeamCity before 2021.2.1, XXE during the parsing of the configuration file was possible. Teamcity 2021.2.1+ Fix from $2,3002022-02-25 HIGH 7.1 CVE-2020-14478 A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote conten… Factorytalk Services Platform after 6.11.00 Fix from $1,9502022-02-24 HIGH 8.8 CVE-2022-25209 Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Chef Sinatra after 1.20 Fix from $1,9502022-02-15 HIGH 7.8 CVE-2021-46365 An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file. Magnolia Cms 6.2.4+ Fix from $1,9502022-02-11 HIGH 7.5 CVE-2022-21205 Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an u… Quartus Prime 21.3+ Fix from $1,9502022-02-09 HIGH 7.8 CVE-2022-21220 Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentia… Quartus Prime 21.3+ Fix from $1,9502022-02-09 CRITICAL 9.8 CVE-2021-46660 Signiant Manager+Agents before 15.1 allows XML External Entity (XXE) attacks. Manager\+agents 15.1+ Fix from $2,3002022-01-30 HIGH 8.2 CVE-2020-4875 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Cognos Controller Mitigation only Fix from $1,9502022-01-21 HIGH 8.2 CVE-2020-4876 IBM Cognos Controller 10.4.0, 10.4.1, and 10.4.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Cognos Controller Mitigation only Fix from $1,9502022-01-21 MEDIUM 5.5 CVE-2022-0219 Improper Restriction of XML External Entity Reference in GitHub repository skylot/jadx prior to 1.3.2. Jadx 1.3.2+ Fix from $1,6002022-01-20 MEDIUM 5.3 CVE-2022-21282 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec… Debian Linux after 15.0.5 Fix from $1,6002022-01-19 CRITICAL 9.8 CVE-2022-0239 corenlp is vulnerable to Improper Restriction of XML External Entity Reference Corenlp 4.4.0+ Fix from $2,3002022-01-17 CRITICAL 9.8 CVE-2021-40722 AEM Forms Cloud Service offering, as well as version 6.5.10.0 (and below) are affected by an XML External Entity (XXE) injection vulnerability that c… Experience Manager after 6.5.10.0 Fix from $2,3002022-01-13 HIGH 7.1 CVE-2022-0198 corenlp is vulnerable to Improper Restriction of XML External Entity Reference Corenlp after 4.3.2 Fix from $1,9502022-01-13 HIGH 8.8 CVE-2021-42560 An issue was discovered in CALDERA 2.9.0. The Debrief plugin receives base64 encoded "SVG" parameters when generating a PDF document. These SVG docum… Caldera No fix yet Fix from $1,9502022-01-12 MEDIUM 5.5 CVE-2021-44028 XXE can occur in Quest KACE Desktop Authority before 11.2 because the log4net configuration file might be controlled by an attacker, a related issue … Kace Desktop Authority 11.2+ Fix from $1,6002021-12-22 MEDIUM 5.5 CVE-2021-3836 dbeaver is vulnerable to Improper Restriction of XML External Entity Reference Dbeaver 21.2.3+ Fix from $1,6002021-12-14 CRITICAL 9.1 CVE-2021-23463 The package com.h2database:h2 from 1.4.198 and before 2.0.202 are vulnerable to XML External Entity (XXE) Injection via the org.h2.jdbc.JdbcSQLXML cl… H2 2.0.202+ Fix from $2,3002021-12-10 CRITICAL 9.1 CVE-2021-44557 National Library of the Netherlands multiNER <= c0440948057afc6e3d6b4903a7c05e666b94a3bc is affected by an XML External Entity (XXE) vulnerability in… Multiner 08-25-2021+ Fix from $2,3002021-12-08 CRITICAL 9.1 CVE-2021-44556 National Library of the Netherlands digger < 6697d1269d981e35e11f240725b16401b5ce3db5 is affected by a XML External Entity (XXE) vulnerability. Since… Digger 08-25-2021+ Fix from $2,3002021-12-08 HIGH 7.7 CVE-2021-42776 CloverDX Server before 5.11.2 and and 5.12.x before 5.12.1 allows XXE during configuration import. Cloverdx 5.11.2+ Fix from $1,9502021-12-01 MEDIUM 5.5 CVE-2021-44147 An XML External Entity issue in Claris FileMaker Pro and Server (including WebDirect) before 19.4.1 allows a remote attacker to disclose local files … Filemaker Pro 19.4.1+ Fix from $1,6002021-11-22 MEDIUM 6.5 CVE-2021-21701 Jenkins Performance Plugin 3.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Performance after 3.20 Fix from $1,6002021-11-12 MEDIUM 6.5 CVE-2021-43576 Jenkins pom2config Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing attackers with Ove… Pom2config after 1.2 Fix from $1,6002021-11-12 HIGH 7.1 CVE-2021-43577 Jenkins OWASP Dependency-Check Plugin 5.1.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Owasp Dependency Check after 5.1.1 Fix from $1,9502021-11-12 HIGH 8.1 CVE-2021-36172 An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attack… Fortiportal 5.3.7 / 6.0.6+ Fix from $1,9502021-11-02