Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2021-20838 Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti… Office Server Document Converter 5.2+ Fix from $1,9502021-11-01 MEDIUM 6.5 CVE-2021-20839 Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti… Office Server Document Converter 5.2+ Fix from $1,6002021-11-01 CRITICAL 9.1 CVE-2020-26705 The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensi… Easyxml Patch available Fix from $2,3002021-10-31 CRITICAL 9.1 CVE-2020-25911 A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information di… Modx Revolution Patch available Fix from $2,3002021-10-31 CRITICAL 9.1 CVE-2020-25912 A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an informa… Symphony Mitigation only Fix from $2,3002021-10-31 HIGH 7.5 CVE-2021-3869 corenlp is vulnerable to Improper Restriction of XML External Entity Reference Corenlp after 4.3.0 Fix from $1,9502021-10-19 CRITICAL 9.8 CVE-2021-3878 corenlp is vulnerable to Improper Restriction of XML External Entity Reference Corenlp 4.3.1+ Fix from $2,3002021-10-15 HIGH 7.5 CVE-2020-19954 An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files. S Cms No fix yet Fix from $1,9502021-10-14 MEDIUM 6.5 CVE-2021-20801 Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information s… Remote Service Manager Mitigation only Fix from $1,6002021-10-13 HIGH 7.5 CVE-2021-35496 The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO Jas… Jasperreports Server after 7.9.0 Fix from $1,9502021-10-12 HIGH 7.5 CVE-2021-40500 SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v… Businessobjects Business Intelligence Platform Mitigation only Fix from $1,9502021-10-12 MEDIUM 6.5 CVE-2021-3312 An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfil… Opencms No fix yet Fix from $1,6002021-10-08 CRITICAL 9.8 CVE-2021-38298 Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE. Manageengine Admanager Plus 7.1+ Fix from $2,3002021-10-07 MEDIUM 6.5 CVE-2021-40439 Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia… Openoffice after 4.1.10 Fix from $1,6002021-10-07 HIGH 7.5 CVE-2021-41770 Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure. Pingfederate 10.3.1+ Fix from $1,9502021-10-07 MEDIUM 5.4 CVE-2021-34706 A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access… Identity Services Engine after 3.1 Fix from $1,6002021-10-06 MEDIUM 6.5 CVE-2021-35201 NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks. Ngeniusone Mitigation only Fix from $1,6002021-09-30 HIGH 7.5 CVE-2021-41098 Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby onl… Nokogiri 1.12.5+ Fix from $1,9502021-09-27 HIGH 8.1 CVE-2021-29831 IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when proce… Jazz For Service Management Patch available Fix from $1,9502021-09-21 HIGH 7.5 CVE-2021-39239 A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex… Jena after 4.1.0 Fix from $1,9502021-09-16 HIGH 8.2 CVE-2021-30137 Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It … Assyst No fix yet Fix from $1,9502021-09-15 HIGH 7.5 CVE-2021-40356 A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al… Teamcenter Visualization 12.4.0.8 / 13.0.0.7+ Fix from $1,9502021-09-14 CRITICAL 9.1 CVE-2021-38555 An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X… Any23 2.5+ Fix from $2,3002021-09-11 MEDIUM 6.5 CVE-2021-3055 An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated … Pan Os 8.1.20 / 9.0.14+ Fix from $1,6002021-09-08 CRITICAL 9.8 CVE-2021-34436 In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. T… Theia after 0.2.0 Fix from $2,3002021-09-02 HIGH 7.1 CVE-2021-21680 Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks. Nested View after 1.20 Fix from $1,9502021-08-31 HIGH 7.5 CVE-2021-39371 An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a pat… Debian Linux 4.4.5+ Fix from $1,9502021-08-23 CRITICAL 9.8 CVE-2020-18703 XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'. Quokka Patch available Fix from $2,3002021-08-16 CRITICAL 9.8 CVE-2020-18705 XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'. Quokka Patch available Fix from $2,3002021-08-16 CRITICAL 9.1 CVE-2021-34823 The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows una… Screenshare 2.0+ Fix from $2,3002021-08-13