Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
CRITICAL 9.1 CVE-2021-27741 " Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection" Hcl Commerce after 9.1.5 Fix from $2,3002021-08-13 HIGH 7.2 CVE-2021-38584 The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585). Cpanel 98.0.1+ Fix from $1,9502021-08-11 CRITICAL 9.1 CVE-2021-37425EPSS 66% Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobi… Mobiletogether Server 7.3+ Fix from $2,3002021-08-10 MEDIUM 5.5 CVE-2021-37178 A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying… Solid Edge Se2021 Firmware Mitigation only Fix from $1,6002021-08-10 HIGH 7.5 CVE-2021-1630 XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pi… Mule 4.3.0+ Fix from $1,9502021-08-05 MEDIUM 6.5 CVE-2020-26564 ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic sur… Opinio 7.15+ Fix from $1,6002021-07-31 CRITICAL 9.8 CVE-2021-23418 The package glances before 3.2.1 are vulnerable to XML External Entity (XXE) Injection via the use of Fault to parse untrusted XML data, which is kno… Glances 3.2.1+ Fix from $2,3002021-07-29 CRITICAL 9.1 CVE-2021-20399 IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.… Qradar Security Information And Event Manager 7.3.3 / 7.4.3+ Fix from $2,3002021-07-27 HIGH 7.6 CVE-2021-22523 XML External Entity vulnerability in Micro Focus Verastream Host Integrator, affecting version 7.8 Update 1 and earlier versions. The vulnerability c… Verastream Host Integrator 7.8+ Fix from $1,9502021-07-22 MEDIUM 5.3 CVE-2021-2401EPSS 85% Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affecte… Bi Publisher Mitigation only Fix from $1,6002021-07-21 HIGH 8.1 CVE-2020-5323 Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection v… Emc Openmanage Enterprise 1.10.00 / 3.2+ Fix from $1,9502021-07-19 HIGH 8.2 CVE-2019-3752 Dell EMC Avamar Server versions 7.4.1, 7.5.0, 7.5.1, 18.2 and 19.1 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1, 2.2, 2… Emc Avamar Server Patch available Fix from $1,9502021-07-16 HIGH 8.2 CVE-2021-20595 Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver… G 50a Firmware after 7.09 Fix from $1,9502021-07-13 MEDIUM 5.3 CVE-2021-32754 FlowDroid is a data flow analysis tool. FlowDroid versions prior to 2.9.0 contained an XML external entity (XXE) vulnerability that allowed an attack… Flowdroid 2.9.0+ Fix from $1,6002021-07-12 HIGH 7.5 CVE-2021-30201EPSS 25% The API /vsaWS/KaseyaWS.asmx can be used to submit XML to the system. When this XML is processed (external) entities are insecurely processed and fet… Vsa 9.5.6+ Fix from $1,9502021-07-09 MEDIUM 5.5 CVE-2021-32972 Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access… Fpwin Pro after 7.5.1.1 Fix from $1,6002021-07-09 HIGH 7.5 CVE-2012-1102 It was discovered that the XML::Atom Perl module before version 0.39 did not disable external entities when parsing XML from potentially untrusted so… \ 0.39+ Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-25951 XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service. Xml2dict No fix yet Fix from $1,9502021-06-30 MEDIUM 5.3 CVE-2021-22338 There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML messa… Ecns280 Firmware Mitigation only Fix from $1,6002021-06-29 HIGH 7.5 CVE-2021-29620 Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortun… Service Api 5.4.0+ Fix from $1,9502021-06-23 CRITICAL 9.8 CVE-2021-35066 An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132. Automate 2021.0.6.132+ Fix from $2,3002021-06-21 HIGH 7.5 CVE-2021-33813EPSS 19% An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. Solr after 2.0.6 Fix from $1,9502021-06-16 CRITICAL 9.1 CVE-2020-5003 IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker co… Financial Transaction Manager Mitigation only Fix from $2,3002021-06-11 MEDIUM 6.5 CVE-2021-27635 SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network an… Netweaver Application Server For Java Patch available Fix from $1,6002021-06-09 HIGH 7.1 CVE-2019-4730 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e… Cognos Analytics Patch available Fix from $1,9502021-06-01 HIGH 8.2 CVE-2020-4300 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e… Cognos Analytics Patch available Fix from $1,9502021-06-01 MEDIUM 5.5 CVE-2021-27492 When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dRe… Crosscadware after 2021.1 Fix from $1,6002021-05-27 HIGH 8.2 CVE-2021-20492 IBM WebSphere Application Server 8.0, 8.5, 9.0, and Liberty Java Batch is vulnerable to an XML External Entity Injection (XXE) attack when processing… Websphere Application Server after 21.0.0.5 Fix from $1,9502021-05-26 MEDIUM 6.5 CVE-2021-32925 admin/user_import.php in Chamilo 1.11.x reads XML data without disabling the ability to load external entities. Chamilo after 1.11.16 Fix from $1,6002021-05-13 HIGH 7.5 CVE-2021-22140 Elastic App Search versions after 7.11.0 and before 7.12.0 contain an XML External Entity Injection issue (XXE) in the App Search web crawler beta fe… Elastic App Search 7.12.0+ Fix from $1,9502021-05-13