Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2021-27741
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
Hcl Commerce
after 9.1.5
HIGH 7.2
CVE-2021-38584
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
Cpanel
98.0.1+
CRITICAL 9.1
CVE-2021-37425EPSS 66%
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobi…
Mobiletogether Server
7.3+
MEDIUM 5.5
CVE-2021-37178
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying…
Solid Edge Se2021 Firmware
Mitigation only
HIGH 7.5
CVE-2021-1630
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pi…
Mule
4.3.0+
MEDIUM 6.5
CVE-2020-26564
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic sur…
Opinio
7.15+
CRITICAL 9.8
CVE-2021-23418
The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is kno…
Glances
3.2.1+
CRITICAL 9.1
CVE-2021-20399
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.…
Qradar Security Information And Event Manager
7.3.3 / 7.4.3+
HIGH 7.6
CVE-2021-22523
XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability c…
Verastream Host Integrator
7.8+
MEDIUM 5.3
CVE-2021-2401EPSS 85%
Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affecte…
Bi Publisher
Mitigation only
HIGH 8.1
CVE-2020-5323
Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v…
Emc Openmanage Enterprise
1.10.00 / 3.2+
HIGH 8.2
CVE-2019-3752
Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2…
Emc Avamar Server
Patch available
HIGH 8.2
CVE-2021-20595
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver…
G 50a Firmware
after 7.09
MEDIUM 5.3
CVE-2021-32754
FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attack…
Flowdroid
2.9.0+
HIGH 7.5
CVE-2021-30201EPSS 25%
The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet…
Vsa
9.5.6+
MEDIUM 5.5
CVE-2021-32972
Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access…
Fpwin Pro
after 7.5.1.1
HIGH 7.5
CVE-2012-1102
It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted so…
\
0.39+
HIGH 7.5
CVE-2021-25951
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
Xml2dict
No fix yet
MEDIUM 5.3
CVE-2021-22338
There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML messa…
Ecns280 Firmware
Mitigation only
HIGH 7.5
CVE-2021-29620
Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortun…
Service Api
5.4.0+
CRITICAL 9.8
CVE-2021-35066
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Automate
2021.0.6.132+
HIGH 7.5
CVE-2021-33813EPSS 19%
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
Solr
after 2.0.6
CRITICAL 9.1
CVE-2020-5003
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co…
Financial Transaction Manager
Mitigation only
MEDIUM 6.5
CVE-2021-27635
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network an…
Netweaver Application Server For Java
Patch available
HIGH 7.1
CVE-2019-4730
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…
Cognos Analytics
Patch available
HIGH 8.2
CVE-2020-4300
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…
Cognos Analytics
Patch available
MEDIUM 5.5
CVE-2021-27492
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dRe…
Crosscadware
after 2021.1
HIGH 8.2
CVE-2021-20492
IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing…
Websphere Application Server
after 21.0.0.5
MEDIUM 6.5
CVE-2021-32925
admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities.
Chamilo
after 1.11.16
HIGH 7.5
CVE-2021-22140
Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe…
Elastic App Search
7.12.0+