Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.0 CVE-2019-18943 Micro Focus Solutions Business Manager versions prior to 11.7.1 are vulnerable to XML External Entity Processing (XXE) on certain operations. Solutions Business Manager 11.7.1+ Fix from $1,9502021-02-26 HIGH 7.5 CVE-2021-27184 Pelco Digital Sentry Server 7.18.72.11464 has an XML External Entity vulnerability (exploitable via the DTD parameter entities technique), resulting … Digital Sentry Server No fix yet Fix from $1,9502021-02-11 HIGH 8.2 CVE-2021-20353EPSS 5% IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Websphere Application Server 7.0.0.45 / 8.0.0.15+ Fix from $1,9502021-02-10 MEDIUM 5.0 CVE-2021-21266 openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML extern… Openhab 2.5.12+ Fix from $1,6002021-02-01 HIGH 8.2 CVE-2020-4949 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Websphere Application Server after 9.0.5.6 Fix from $1,9502021-01-26 CRITICAL 9.1 CVE-2021-23901 An XML external entity (XXE) injection vulnerability was discovered in the Nutch DmozParser and is known to affect Nutch versions < 1.18. XML externa… Nutch 1.18+ Fix from $2,3002021-01-25 HIGH 7.5 CVE-2020-27858EPSS 74% This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5. Authentication is not… D2d Mitigation only Fix from $1,9502021-01-20 HIGH 8.1 CVE-2021-22498 XML External Entity Injection vulnerability in Micro Focus Application Lifecycle Management (Previously known as Quality Center) product. The vulnera… Application Lifecycle Management after 15.0.1 Fix from $1,9502021-01-19 CRITICAL 9.8 CVE-2021-23899 OWASP json-sanitizer before 1.2.2 may emit closing SCRIPT tags and CDATA section delimiters for crafted input. This allows an attacker to inject arbi… Json Sanitizer 1.2.2+ Fix from $2,3002021-01-13 MEDIUM 6.5 CVE-2020-26981 A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially cr… Jt2go 13.1.0+ Fix from $1,6002021-01-12 HIGH 7.1 CVE-2020-27148 The TIBCO EBX Add-on for Oracle Hyperion EPM, TIBCO EBX Data Exchange Add-on, and TIBCO EBX Insight Add-on components of TIBCO Software Inc.'s TIBCO … Ebx Add Ons after 4.4.2 Fix from $1,9502021-01-12 HIGH 8.8 CVE-2020-28734 Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role. Plone 5.2.3+ Fix from $1,9502020-12-30 HIGH 8.8 CVE-2020-28736 Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, onl… Plone 5.2.3+ Fix from $1,9502020-12-30 CRITICAL 9.8 CVE-2020-35604 An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used. Web Time And Attendance No fix yet Fix from $2,3002020-12-21 MEDIUM 6.5 CVE-2020-35123 In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store exten… Collaboration 8.8.15+ Fix from $1,6002020-12-17 MEDIUM 6.5 CVE-2020-29436 Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of … Nexus Repository Manager 3.29.0+ Fix from $1,6002020-12-17 MEDIUM 5.5 CVE-2020-26513 An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import project… Codebeamer 10.1.0+ Fix from $1,6002020-12-07 HIGH 7.5 CVE-2020-25649EPSS 18% A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML extern… Fedora 0.12.0 / 2.6.7.4+ Fix from $1,9502020-12-03 HIGH 7.5 CVE-2020-2324 Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Cvs after 2.16 Fix from $1,9502020-12-03 HIGH 8.8 CVE-2020-7572 A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that co… Webreports after 3.1 Fix from $1,9502020-11-19 MEDIUM 6.5 CVE-2020-7032 An XML external entity (XXE) vulnerability in Avaya WebLM admin interface allows authenticated users to read arbitrary files or conduct server-side r… Aura System Manager 8.1.3+ Fix from $1,6002020-11-13 HIGH 7.5 CVE-2020-24454 Improper Restriction of XML External Entity Reference in subsystem forIntel(R) Quartus(R) Prime Pro Edition before version 20.3 and Intel(R) Quartus(… Quartus Prime 20.3+ Fix from $1,9502020-11-12 HIGH 7.2 CVE-2020-15352 An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authen… Connect Secure after 9.0 Fix from $1,9502020-10-27 HIGH 7.5 CVE-2020-25186 An XXE vulnerability exists within LeviStudioU Release Build 2019-09-21 and prior when processing parameter entities, which may allow file disclosure. Levistudiou after 2019-09-21 Fix from $1,9502020-10-22 HIGH 8.1 CVE-2020-4772 An XML External Entity Injection (XXE) vulnerability may impact IBM Curam Social Program Management 7.0.9 and 7.0.10. A remote attacker could exploit… Curam Social Program Management Mitigation only Fix from $1,9502020-10-12 CRITICAL 9.1 CVE-2020-15232 In mapfish-print before version 3.24, a user can do to an XML External Entity (XXE) attack with the provided SDL style. Print 3.24+ Fix from $2,3002020-10-02 MEDIUM 5.5 CVE-2020-13940 In Apache NiFi 1.0.0 to 1.11.4, the notification service manager and various policy authorizer and user group provider objects allowed trusted admini… Nifi after 1.11.4 Fix from $1,6002020-10-01 CRITICAL 9.1 CVE-2020-21524 There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/word… Halo No fix yet Fix from $2,3002020-09-30 HIGH 7.1 CVE-2020-2284 Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Liquibase Runner after 1.4.5 Fix from $1,9502020-09-23 HIGH 7.5 CVE-2020-4643 IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Websphere Application Server after 9.0.5.5 Fix from $1,9502020-09-21