Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.7 CVE-2020-13692 PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. Postgresql Jdbc Driver 42.2.13+ Fix from $1,9502020-06-04 HIGH 7.6 CVE-2020-4509 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit … Qradar Security Information And Event Manager Mitigation only Fix from $1,9502020-06-04 HIGH 7.1 CVE-2020-4246 IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Security Identity Governance And Intelligence Patch available Fix from $1,9502020-05-28 HIGH 7.5 CVE-2020-2012 Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthent… Pan Os 8.1.13 / 9.0.7+ Fix from $1,9502020-05-13 CRITICAL 9.8 CVE-2018-1285EPSS 17% Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack… Log4net 2.0.10+ Fix from $2,3002020-05-11 MEDIUM 5.5 CVE-2020-11541 In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data u… Snagit after 20.0.3 Fix from $1,6002020-05-08 HIGH 7.2 CVE-2020-12719 XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, A… Api Manager after 6.4.0 Fix from $1,9502020-05-08 HIGH 7.5 CVE-2020-12642 An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSR… Service Api 4.3.12 / 5.1.1+ Fix from $1,9502020-05-04 CRITICAL 9.8 CVE-2020-10683EPSS 7% dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po… Ubuntu Linux 2.0.3 / 2.1.3+ Fix from $2,3002020-05-01 HIGH 7.2 CVE-2020-11885 WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend… Enterprise Integrator after 6.6.0 Fix from $1,9502020-04-17 HIGH 7.1 CVE-2020-2178 Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Parasoft Findings after 10.4.3 Fix from $1,9502020-04-16 CRITICAL 9.3 CVE-2020-6238 SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing … Commerce Cloud Mitigation only Fix from $2,3002020-04-14 HIGH 7.5 CVE-2020-10629 WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files. Webaccess\/nms 3.0.2+ Fix from $1,9502020-04-09 HIGH 8.2 CVE-2019-4391 HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data Appscan after 9.0.3.14 Fix from $1,9502020-04-07 CRITICAL 9.8 CVE-2020-11586 An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XM… Cipace 9.1+ Fix from $2,3002020-04-06 CRITICAL 9.8 CVE-2020-10990 An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component. Mercury 1.12.28+ Fix from $2,3002020-03-27 CRITICAL 9.8 CVE-2020-10991 Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java Aplkit after 1.3.0 Fix from $2,3002020-03-27 CRITICAL 9.8 CVE-2020-10992 Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java. Azkaban after 3.84.0 Fix from $2,3002020-03-27 CRITICAL 9.1 CVE-2020-10993 Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java. Osmand after 2.0.0 Fix from $2,3002020-03-27 HIGH 8.8 CVE-2020-2171 Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Rapiddeploy after 4.2 Fix from $1,9502020-03-25 CRITICAL 9.8 CVE-2019-20627 AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. Autoupdater.net 1.5.8+ Fix from $2,3002020-03-23 CRITICAL 9.8 CVE-2020-10799 The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call. Svglib after 0.9.3 Fix from $2,3002020-03-20 HIGH 7.5 CVE-2019-20191 Oxygen XML Editor 21.1.1 allows XXE to read any file. Oxygen Xml Author after 21.1.1 Fix from $1,9502020-03-16 CRITICAL 9.8 CVE-2020-8540EPSS 13% An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to … Manageengine Desktop Central 2020-03-07+ Fix from $2,3002020-03-11 CRITICAL 9.1 CVE-2020-9044 XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII serve… Metasys Application And Data Server after 13.2 Fix from $2,3002020-03-10 HIGH 7.1 CVE-2020-2144 Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Rundeck after 3.6.6 Fix from $1,9502020-03-09 HIGH 7.1 CVE-2020-2138 Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. Cobertura after 1.15 Fix from $1,9502020-03-09 CRITICAL 9.8 CVE-2020-9352 An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST reques… Smartclient No fix yet Fix from $2,3002020-02-23 CRITICAL 9.8 CVE-2020-1693 A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated … Spacewalk 2.9+ Fix from $2,3002020-02-17 MEDIUM 5.5 CVE-2019-6194 An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow i… Xclarity Administrator 2.6.6+ Fix from $1,6002020-02-14