Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2020-1975
Missing XML validation vulnerability in the PAN-OS web interface on Palo Alto Networks PAN-OS software allows authenticated users to inject arbitrary…
Pan Os
8.1.12 / 9.0.6+
HIGH 8.8
CVE-2020-2115
Jenkins NUnit Plugin 0.25 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
Nunit
after 0.25
HIGH 8.8
CVE-2020-2120
Jenkins FitNesse Plugin 1.30 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks.
Fitnesse
after 1.30
CRITICAL 9.8
CVE-2014-2052
Zend Framework, as used in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2, allows remote attackers to read arbitrary files, cause a denial of s…
Owncloud
5.0.15 / 6.0.2+
CRITICAL 9.8
CVE-2013-4334
opWebAPIPlugin 0.5.1, 0.4.0, and 0.1.0: XXE Vulnerabilities
Opwebapiplugin
Patch available
MEDIUM 5.3
CVE-2019-10782
All versions of com.puppycrawl.tools:checkstyle before 8.29 are vulnerable to XML External Entity (XXE) Injection due to an incomplete fix for CVE-20…
Checkstyle
8.29+
HIGH 7.6
CVE-2020-2108
Jenkins WebSphere Deployer Plugin 1.6.1 and earlier does not configure the XML parser to prevent XXE attacks which can be exploited by a user with Jo…
Websphere Deployer
after 1.6.1
HIGH 7.1
CVE-2019-4707
IBM Security Access Manager Appliance 9.0.7.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attac…
Security Access Manager
Mitigation only
CRITICAL 9.1
CVE-2013-4333
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
Openpne
Patch available
HIGH 7.5
CVE-2015-1809
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …
Cloudbees
1.596.1 / 1.600+
HIGH 7.5
CVE-2015-1811
XML external entity (XXE) vulnerability in CloudBees Jenkins before 1.600 and LTS before 1.596.1 allows remote attackers to read arbitrary XML files …
Cloudbees
1.596.1 / 1.600+
HIGH 7.5
CVE-2019-18412
JetBrains IDETalk plugin before version 193.4099.10 allows XXE
Idetalk
193.4099.10+
HIGH 8.8
CVE-2020-2092
Jenkins Robot Framework Plugin 2.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, allowing users with …
Robot Framework
after 2.0.0
HIGH 7.1
CVE-2015-8549
XML external entity (XXE) vulnerability in PyAMF before 0.8.0 allows remote attackers to cause a denial of service or read arbitrary files via a craf…
Pyamf
0.8.0+
HIGH 7.8
CVE-2014-5238
XML external entity (XXE) vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev11 and 7.6.x before 7.6.0-rev9 allows remote attackers to read …
Open Xchange Appsuite
after 7.4.1
CRITICAL 9.1
CVE-2020-6958
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to …
Yet Another Java Service Wrapper
No fix yet
MEDIUM 6.5
CVE-2019-17020
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied …
Firefox
72.0+
MEDIUM 6.5
CVE-2019-3768
RSA Authentication Manager versions prior to 8.4 P7 contain an XML Entity Injection Vulnerability. A remote authenticated malicious user could potent…
Rsa Authentication Manager
8.4+
HIGH 8.1
CVE-2019-19031EPSS 5%
Easy XML Editor through v1.7.8 is affected by: XML External Entity Injection. The impact is: Arbitrary File Read and DoS by consuming resources. The …
Easy Xml Editor
after 1.7.8
HIGH 8.1
CVE-2019-19032
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an XML File is validated. The co…
Xmlblueprint
after 16.191112
HIGH 7.5
CVE-2019-19998
Xiuno BBS 4.0 allows XXE via plugin/xn_wechat_public/route/token.php.
Xiunobbs
No fix yet
HIGH 7.5
CVE-2012-2656
An XML eXternal Entity (XXE) issue exists in Restlet 1.1.10 in an endpoint using XML transport, which lets a remote attacker obtain sensitive informa…
Restlet
Patch available
HIGH 8.1
CVE-2019-16549
Jenkins Maven Release Plugin 0.16.1 and earlier does not configure the XML parser to prevent XML external entity (XXE) attacks, allowing man-in-the-m…
Maven
after 0.16.1
HIGH 7.5
CVE-2014-3643
jersey: XXE via parameter entities not disabled by the jersey SAX parser
Jersey
Mitigation only
HIGH 7.5
CVE-2019-19702
The modoboa-dmarc plugin 1.1.0 for Modoboa is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…
Modoboa Dmarc
No fix yet
MEDIUM 6.5
CVE-2019-11216
BMC Smart Reporting 7.3 20180418 allows authenticated XXE within the import functionality. One can import a malicious XML file and perform XXE attack…
Remedy Smart Reporting
after 19.02.01
MEDIUM 5.5
CVE-2019-17554EPSS 12%
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resolution of external entities. Requ…
Olingo
after 4.6.0
HIGH 7.5
CVE-2011-3600EPSS 16%
The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with exe…
Ofbiz
after 16.11.04
MEDIUM 6.5
CVE-2019-10080
The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML f…
Nifi
after 1.9.2
MEDIUM 6.5
CVE-2019-17085
XXE attack vulnerability on Micro Focus Operations Agent, affected version 12.0, 12.01, 12.02, 12.03, 12.04, 12.05, 12.06, 12.10, 12.11. The vulnerab…
Operations Agent
Mitigation only