Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2018-20687
An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote una…
Commandcenter Secure Gateway
8.0.0+
HIGH 7.5
CVE-2019-10172EPSS 17%
A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c…
Jboss Enterprise Application Platform
after 1.9.13
CRITICAL 10.0
CVE-2019-14678
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local …
Xml Mapper
Mitigation only
MEDIUM 6.5
CVE-2014-3599
HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy
Hornetq
after 2.4.5
HIGH 8.8
CVE-2019-12331
PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is …
Phpspreadsheet
1.8.0+
HIGH 7.5
CVE-2019-18227
Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data.
Wise Paas\/rmm
after 3.3.29
HIGH 7.5
CVE-2019-9757EPSS 37%
An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualiza…
Labkey Server
No fix yet
HIGH 7.5
CVE-2017-15725
An XML External Entity Injection vulnerability exists in Dzone AnswerHub.
Dzone Answerhub
No fix yet
HIGH 7.5
CVE-2019-8086EPSS 23%
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…
Experience Manager
Mitigation only
HIGH 7.5
CVE-2019-8087
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen…
Experience Manager
Mitigation only
HIGH 7.5
CVE-2019-8082
Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitiv…
Experience Manager
Mitigation only
HIGH 8.8
CVE-2019-18213
XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other pro…
Xml Server Project
0.9.1+
MEDIUM 5.5
CVE-2019-12415
In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can a…
Poi
after 4.1.0
HIGH 8.1
CVE-2019-10466
An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa…
360 Fireline
after 1.7.2
MEDIUM 6.5
CVE-2019-14276
WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
Xnat
Patch available
HIGH 8.8
CVE-2019-1060EPSS 14%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
MEDIUM 6.5
CVE-2019-12711
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Editio…
Unified Communications Manager
Mitigation only
HIGH 7.1
CVE-2019-16188
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a sp…
Appscan Source
9.03.13+
HIGH 8.8
CVE-2019-16174
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute …
Limesurvey
3.17.14+
HIGH 7.5
CVE-2019-6179
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity I…
Xclarity Administrator
2.5.0 / 6.1.0+
HIGH 7.5
CVE-2019-13608 KEVEPSS 30%
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Storefront Server
3.0.8000 / 3.12.4000+
MEDIUM 6.5
CVE-2019-15641
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi.
Webmin
after 1.930
HIGH 8.1
CVE-2019-15637EPSS 14%
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This…
Tableau Server
after 2019.2.2
HIGH 8.2
CVE-2019-4513
IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da…
Security Access Manager For Enterprise Single Sign On
Mitigation only
HIGH 7.5
CVE-2019-14258
The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988.
Zenoss
No fix yet
HIGH 8.2
CVE-2019-4340
IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r…
Security Guardium Big Data Intelligence
Mitigation only
HIGH 8.2
CVE-2019-4424
IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack …
Business Automation Workflow
after 19.0.0.2
HIGH 8.2
CVE-2019-4433
IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (…
Infosphere Global Name Management
Mitigation only
HIGH 8.2
CVE-2019-4419
IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…
Intelligent Operations Center
after 5.2.1.1
MEDIUM 5.5
CVE-2019-1187
A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited t…
Windows 10
Patch available