Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2021-20838
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti…
Office Server Document Converter
5.2+
MEDIUM 6.5
CVE-2021-20839
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Enti…
Office Server Document Converter
5.2+
CRITICAL 9.1
CVE-2020-26705
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensi…
Easyxml
Patch available
CRITICAL 9.1
CVE-2020-25911
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information di…
Modx Revolution
Patch available
CRITICAL 9.1
CVE-2020-25912
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an informa…
Symphony
Mitigation only
HIGH 7.5
CVE-2021-3869
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
Corenlp
after 4.3.0
CRITICAL 9.8
CVE-2021-3878
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
Corenlp
4.3.1+
HIGH 7.5
CVE-2020-19954
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
S Cms
No fix yet
MEDIUM 6.5
CVE-2021-20801
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information s…
Remote Service Manager
Mitigation only
HIGH 7.5
CVE-2021-35496
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO Jas…
Jasperreports Server
after 7.9.0
HIGH 7.5
CVE-2021-40500
SAP BusinessObjects Business Intelligence Platform (Crystal Reports) - versions 420, 430, allows an unauthenticated attacker to exploit missing XML v…
Businessobjects Business Intelligence Platform
Mitigation only
MEDIUM 6.5
CVE-2021-3312
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfil…
Opencms
No fix yet
CRITICAL 9.8
CVE-2021-38298
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
Manageengine Admanager Plus
7.1+
MEDIUM 6.5
CVE-2021-40439
Apache OpenOffice has a dependency on expat software. Versions prior to 2.1.0 were subject to CVE-2013-0340 a "Billion Laughs" entity expansion denia…
Openoffice
after 4.1.10
HIGH 7.5
CVE-2021-41770
Ping Identity PingFederate before 10.3.1 mishandles pre-parsing validation, leading to an XXE attack that can achieve XML file disclosure.
Pingfederate
10.3.1+
MEDIUM 5.4
CVE-2021-34706
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to access…
Identity Services Engine
after 3.1
MEDIUM 6.5
CVE-2021-35201
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
Ngeniusone
Mitigation only
HIGH 7.5
CVE-2021-41098
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri v1.12.4 and earlier, on JRuby onl…
Nokogiri
1.12.5+
HIGH 8.1
CVE-2021-29831
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI is vulnerable to an XML External Entity Injection (XXE) attack when proce…
Jazz For Service Management
Patch available
HIGH 7.5
CVE-2021-39239
A vulnerability in XML processing in Apache Jena, in versions up to 4.1.0, may allow an attacker to execute XML External Entities (XXE), including ex…
Jena
after 4.1.0
HIGH 8.2
CVE-2021-30137
Assyst 10 SP7.5 has authenticated XXE leading to SSRF via XML unmarshalling. The application allows users to send JSON or XML data to the server. It …
Assyst
No fix yet
HIGH 7.5
CVE-2021-40356
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…
Teamcenter Visualization
12.4.0.8 / 13.0.0.7+
CRITICAL 9.1
CVE-2021-38555
An XML external entity (XXE) injection vulnerability was discovered in the Any23 StreamUtils.java file and is known to affect Any23 versions < 2.5. X…
Any23
2.5+
MEDIUM 6.5
CVE-2021-3055
An improper restriction of XML external entity (XXE) reference vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated …
Pan Os
8.1.20 / 9.0.14+
CRITICAL 9.8
CVE-2021-34436
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. T…
Theia
after 0.2.0
HIGH 7.1
CVE-2021-21680
Jenkins Nested View Plugin 1.20 and earlier does not configure its XML transformer to prevent XML external entity (XXE) attacks.
Nested View
after 1.20
HIGH 7.5
CVE-2021-39371
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a pat…
Debian Linux
4.4.5+
CRITICAL 9.8
CVE-2020-18703
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
Quokka
Patch available
CRITICAL 9.8
CVE-2020-18705
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
Quokka
Patch available
CRITICAL 9.1
CVE-2021-34823
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows una…
Screenshare
2.0+