Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2021-30006 In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure. Intellij Idea 2020.3.3+ Fix from $1,9502021-05-11 MEDIUM 6.5 CVE-2020-36124 Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise … Paxstore after 7.0.8_20200511171508 Fix from $1,6002021-05-07 HIGH 7.1 CVE-2021-1530 A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to … Broadworks Messaging Server Mitigation only Fix from $1,9502021-05-06 HIGH 8.1 CVE-2020-5013 IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit … Qradar Security Information And Event Manager 7.3.3 / 7.4.2+ Fix from $1,9502021-05-05 MEDIUM 5.4 CVE-2021-1369 A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read an… Firepower Device Manager 6.5.0.5 / 6.6.3+ Fix from $1,6002021-04-29 HIGH 8.2 CVE-2021-29140 A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Arub… Clearpass 6.7.13 / 6.8.4+ Fix from $1,9502021-04-29 HIGH 8.1 CVE-2021-25163 A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch… Airwave 8.2.12.1+ Fix from $1,9502021-04-29 HIGH 8.1 CVE-2020-7037 An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to… Equinox Conferencing 9.1.11+ Fix from $1,9502021-04-28 MEDIUM 6.5 CVE-2021-25164 A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch… Airwave 8.2.12.1+ Fix from $1,6002021-04-28 HIGH 8.1 CVE-2021-25165 A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch… Airwave 8.2.12.1+ Fix from $1,9502021-04-28 MEDIUM 6.5 CVE-2020-7035 An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote… Aura Orchestration Designer after 7.2.2 Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2020-7036 An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that … Callback Assist 4.7.1.1+ Fix from $1,6002021-04-23 MEDIUM 6.5 CVE-2021-27736 FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers… Saml V2 0.5.4+ Fix from $1,6002021-04-22 HIGH 8.1 CVE-2021-21642EPSS 38% Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Config File Provider after 3.7.0 Fix from $1,9502021-04-21 HIGH 8.2 CVE-2021-20454 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem… Websphere Application Server after 9.0.5.7 Fix from $1,9502021-04-21 HIGH 8.2 CVE-2021-20453 IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a… Websphere Application Server 8.0.0.15 / 8.5.5.20+ Fix from $1,9502021-04-20 MEDIUM 6.5 CVE-2021-29447EPSS 86% Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leadi… WordPress 5.7.1+ Fix from $1,6002021-04-15 MEDIUM 6.5 CVE-2021-27604 In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Reposi… Netweaver Process Integration Mitigation only Fix from $1,6002021-04-14 HIGH 7.5 CVE-2020-6590 Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure. Data Loss Prevention 8.5.4 / 8.7.1+ Fix from $1,9502021-04-08 HIGH 7.2 CVE-2021-22158 The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. … Insider Threat Management 7.9.3 / 7.10.3+ Fix from $1,9502021-04-06 HIGH 7.5 CVE-2021-29421 models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. Fedora after 2.9.2 Fix from $1,9502021-04-01 HIGH 7.1 CVE-2021-20502 IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploi… Engineering Insights Patch available Fix from $1,9502021-03-30 HIGH 7.1 CVE-2021-20482 IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo… Cloud Pak For Automation Mitigation only Fix from $1,9502021-03-30 CRITICAL 9.8 CVE-2021-1628 MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub a… Mule after 4.2.2 Fix from $2,3002021-03-26 HIGH 7.5 CVE-2021-28110 /exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser. Tranzware E Commerce Payment Gateway 3.1.27.5+ Fix from $1,9502021-03-19 MEDIUM 5.5 CVE-2020-28387 A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a sp… Solid Edge Mitigation only Fix from $1,6002021-03-15 MEDIUM 6.5 CVE-2021-26969 A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to… Airwave 8.2.12.0+ Fix from $1,6002021-03-05 CRITICAL 9.1 CVE-2021-27931EPSS 18% LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a re… Lumis Experience Platform 10.0.0+ Fix from $2,3002021-03-03 CRITICAL 9.8 CVE-2021-26703 EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI. Eprints Patch available Fix from $2,3002021-03-01 HIGH 7.2 CVE-2021-21517 SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supp… Emc Srs Policy Manager Mitigation only Fix from $1,9502021-03-01