Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.7
CVE-2020-13692
PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
Postgresql Jdbc Driver
42.2.13+
HIGH 7.6
CVE-2020-4509
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit …
Qradar Security Information And Event Manager
Mitigation only
HIGH 7.1
CVE-2020-4246
IBM Security Identity Governance and Intelligence 5.2.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…
Security Identity Governance And Intelligence
Patch available
HIGH 7.5
CVE-2020-2012
Improper restriction of XML external entity reference ('XXE') vulnerability in Palo Alto Networks Panorama management service allows remote unauthent…
Pan Os
8.1.13 / 9.0.7+
CRITICAL 9.8
CVE-2018-1285EPSS 17%
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attack…
Log4net
2.0.10+
MEDIUM 5.5
CVE-2020-11541
In TechSmith SnagIt 11.2.1 through 20.0.3, an XML External Entity (XXE) injection issue exists that would allow a local attacker to exfiltrate data u…
Snagit
after 20.0.3
HIGH 7.2
CVE-2020-12719
XXE during an EventPublisher update can occur in Management Console in WSO2 API Manager 3.0.0 and earlier, API Manager Analytics 2.5.0 and earlier, A…
Api Manager
after 6.4.0
HIGH 7.5
CVE-2020-12642
An issue was discovered in service-api before 4.3.12 and 5.x before 5.1.1 for Report Portal. It allows XXE, with resultant secrets disclosure and SSR…
Service Api
4.3.12 / 5.1.1+
CRITICAL 9.8
CVE-2020-10683EPSS 7%
dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…
Ubuntu Linux
2.0.3 / 2.1.3+
HIGH 7.2
CVE-2020-11885
WSO2 Enterprise Integrator through 6.6.0 has an XXE vulnerability where a user (with admin console access) can use the XML validator to make unintend…
Enterprise Integrator
after 6.6.0
HIGH 7.1
CVE-2020-2178
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Parasoft Findings
after 10.4.3
CRITICAL 9.3
CVE-2020-6238
SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing …
Commerce Cloud
Mitigation only
HIGH 7.5
CVE-2020-10629
WebAccess/NMS (versions prior to 3.0.2) does not sanitize XML input. Specially crafted XML input could allow an attacker to read sensitive files.
Webaccess\/nms
3.0.2+
HIGH 8.2
CVE-2019-4391
HCL AppScan Standard is vulnerable to XML External Entity Injection (XXE) attack when processing XML data
Appscan
after 9.0.3.14
CRITICAL 9.8
CVE-2020-11586
An XXE issue was discovered in CIPPlanner CIPAce 9.1 Build 2019092801. An unauthenticated attacker can make an API request that contains malicious XM…
Cipace
9.1+
CRITICAL 9.8
CVE-2020-10990
An XXE issue exists in Accenture Mercury before 1.12.28 because of the platformlambda/core/serializers/SimpleXmlParser.java component.
Mercury
1.12.28+
CRITICAL 9.8
CVE-2020-10991
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
Aplkit
after 1.3.0
CRITICAL 9.8
CVE-2020-10992
Azkaban through 3.84.0 allows XXE, related to validator/XmlValidatorManager.java and user/XmlUserManager.java.
Azkaban
after 3.84.0
CRITICAL 9.1
CVE-2020-10993
Osmand through 2.0.0 allow XXE because of binary/BinaryMapIndexReader.java.
Osmand
after 2.0.0
HIGH 8.8
CVE-2020-2171
Jenkins RapidDeploy Plugin 4.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Rapiddeploy
after 4.2
CRITICAL 9.8
CVE-2019-20627
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
Autoupdater.net
1.5.8+
CRITICAL 9.8
CVE-2020-10799
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
Svglib
after 0.9.3
HIGH 7.5
CVE-2019-20191
Oxygen XML Editor 21.1.1 allows XXE to read any file.
Oxygen Xml Author
after 21.1.1
CRITICAL 9.8
CVE-2020-8540EPSS 13%
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to …
Manageengine Desktop Central
2020-03-07+
CRITICAL 9.1
CVE-2020-9044
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII serve…
Metasys Application And Data Server
after 13.2
HIGH 7.1
CVE-2020-2144
Jenkins Rundeck Plugin 3.6.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Rundeck
after 3.6.6
HIGH 7.1
CVE-2020-2138
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Cobertura
after 1.15
CRITICAL 9.8
CVE-2020-9352
An issue was discovered in SmartClient 12.0. Unauthenticated exploitation of blind XXE can occur in the downloadWSDL feature by sending a POST reques…
Smartclient
No fix yet
CRITICAL 9.8
CVE-2020-1693
A flaw was found in Spacewalk up to version 2.9 where it was vulnerable to XML internal entity attacks via the /rpc/api endpoint. An unauthenticated …
Spacewalk
2.9+
MEDIUM 5.5
CVE-2019-6194
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow i…
Xclarity Administrator
2.6.6+