Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2021-30006
In IntelliJ IDEA before 2020.3.3, XXE was possible, leading to information disclosure.
Intellij Idea
2020.3.3+
MEDIUM 6.5
CVE-2020-36124
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise …
Paxstore
after 7.0.8_20200511171508
HIGH 7.1
CVE-2021-1530
A vulnerability in the web-based management interface of Cisco BroadWorks Messaging Server Software could allow an authenticated, remote attacker to …
Broadworks Messaging Server
Mitigation only
HIGH 8.1
CVE-2020-5013
IBM QRadar SIEM 7.3 and 7.4 may vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …
Qradar Security Information And Event Manager
7.3.3 / 7.4.2+
MEDIUM 5.4
CVE-2021-1369
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to gain read an…
Firepower Device Manager
6.5.0.5 / 6.6.3+
HIGH 8.2
CVE-2021-29140
A remote XML external entity (XXE) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.9, 6.7.14-HF1. Arub…
Clearpass
6.7.13 / 6.8.4+
HIGH 8.1
CVE-2021-25163
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…
Airwave
8.2.12.1+
HIGH 8.1
CVE-2020-7037
An XML External Entities (XXE) vulnerability in Media Server component of Avaya Equinox Conferencing could allow an authenticated, remote attacker to…
Equinox Conferencing
9.1.11+
MEDIUM 6.5
CVE-2021-25164
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…
Airwave
8.2.12.1+
HIGH 8.1
CVE-2021-25165
A remote XML external entity vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patch…
Airwave
8.2.12.1+
MEDIUM 6.5
CVE-2020-7035
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote…
Aura Orchestration Designer
after 7.2.2
MEDIUM 6.5
CVE-2020-7036
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that …
Callback Assist
4.7.1.1+
MEDIUM 6.5
CVE-2021-27736
FusionAuth fusionauth-samlv2 before 0.5.4 allows XXE attacks via a forged AuthnRequest or LogoutRequest because parseFromBytes uses javax.xml.parsers…
Saml V2
0.5.4+
HIGH 8.1
CVE-2021-21642EPSS 38%
Jenkins Config File Provider Plugin 3.7.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Config File Provider
after 3.7.0
HIGH 8.2
CVE-2021-20454
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A rem…
Websphere Application Server
after 9.0.5.7
HIGH 8.2
CVE-2021-20453
IBM WebSphere Application Server 8.0, 8.5, and 9.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…
Websphere Application Server
8.0.0.15 / 8.5.5.20+
MEDIUM 6.5
CVE-2021-29447EPSS 86%
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leadi…
WordPress
5.7.1+
MEDIUM 6.5
CVE-2021-27604
In order to prevent XML External Entity vulnerability in SAP NetWeaver ABAP Server and ABAP Platform (Process Integration - Enterprise Service Reposi…
Netweaver Process Integration
Mitigation only
HIGH 7.5
CVE-2020-6590
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
Data Loss Prevention
8.5.4 / 8.7.1+
HIGH 7.2
CVE-2021-22158
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. …
Insider Threat Management
7.9.3 / 7.10.3+
HIGH 7.5
CVE-2021-29421
models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries.
Fedora
after 2.9.2
HIGH 7.1
CVE-2021-20502
IBM Jazz Foundation Products are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploi…
Engineering Insights
Patch available
HIGH 7.1
CVE-2021-20482
IBM Cloud Pak for Automation 20.0.2 and 20.0.3 IF002 are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remo…
Cloud Pak For Automation
Mitigation only
CRITICAL 9.8
CVE-2021-1628
MuleSoft is aware of a XML External Entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect both CloudHub a…
Mule
after 4.2.2
HIGH 7.5
CVE-2021-28110
/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.
Tranzware E Commerce Payment Gateway
3.1.27.5+
MEDIUM 5.5
CVE-2020-28387
A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP3). When opening a sp…
Solid Edge
Mitigation only
MEDIUM 6.5
CVE-2021-26969
A remote authenticated authenticated xml external entity (xxe) vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to…
Airwave
8.2.12.0+
CRITICAL 9.1
CVE-2021-27931EPSS 18%
LumisXP (aka Lumis Experience Platform) before 10.0.0 allows unauthenticated blind XXE via an API request to PageControllerXml.jsp. One can send a re…
Lumis Experience Platform
10.0.0+
CRITICAL 9.8
CVE-2021-26703
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted JSON/XML input to a cgi/ajax/phrase URI.
Eprints
Patch available
HIGH 7.2
CVE-2021-21517
SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supp…
Emc Srs Policy Manager
Mitigation only