Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
CRITICAL 9.8 CVE-2018-20687 An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote una… Commandcenter Secure Gateway 8.0.0+ Fix from $2,3002019-11-18 HIGH 7.5 CVE-2019-10172EPSS 17% A flaw was found in org.codehaus.jackson:jackson-mapper-asl:1.9.x libraries. XML external entity vulnerabilities similar CVE-2016-3720 also affects c… Jboss Enterprise Application Platform after 1.9.13 Fix from $1,9502019-11-18 CRITICAL 10.0 CVE-2019-14678 SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local … Xml Mapper Mitigation only Fix from $2,3002019-11-14 MEDIUM 6.5 CVE-2014-3599 HornetQ REST is vulnerable to XML External Entity due to insecure configuration of RestEasy Hornetq after 2.4.5 Fix from $1,6002019-11-12 HIGH 8.8 CVE-2019-12331 PHPOffice PhpSpreadsheet before 1.8.0 has an XXE issue. The XmlScanner decodes the sheet1.xml from an .xlsx to utf-8 if something else than UTF-8 is … Phpspreadsheet 1.8.0+ Fix from $1,9502019-11-07 HIGH 7.5 CVE-2019-18227 Advantech WISE-PaaS/RMM, Versions 3.3.29 and prior. XXE vulnerabilities exist that may allow disclosure of sensitive data. Wise Paas\/rmm after 3.3.29 Fix from $1,9502019-10-31 HIGH 7.5 CVE-2019-9757EPSS 37% An issue was discovered in LabKey Server 19.1.0. Sending an SVG containing an XXE payload to the endpoint visualization-exportImage.view or visualiza… Labkey Server No fix yet Fix from $1,9502019-10-29 HIGH 7.5 CVE-2017-15725 An XML External Entity Injection vulnerability exists in Dzone AnswerHub. Dzone Answerhub No fix yet Fix from $1,9502019-10-28 HIGH 7.5 CVE-2019-8086EPSS 23% Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen… Experience Manager Mitigation only Fix from $1,9502019-10-25 HIGH 7.5 CVE-2019-8087 Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sen… Experience Manager Mitigation only Fix from $1,9502019-10-25 HIGH 7.5 CVE-2019-8082 Adobe Experience Manager versions 6.4, 6.3 and 6.2 have a xml external entity injection vulnerability. Successful exploitation could lead to sensitiv… Experience Manager Mitigation only Fix from $1,9502019-10-25 HIGH 8.8 CVE-2019-18213 XML Language Server (aka lsp4xml) before 0.9.1, as used in Red Hat XML Language Support (aka vscode-xml) before 0.9.1 for Visual Studio and other pro… Xml Server Project 0.9.1+ Fix from $1,9502019-10-23 MEDIUM 5.5 CVE-2019-12415 In Apache POI up to 4.1.0, when using the tool XSSFExportToXml to convert user-provided Microsoft Excel documents, a specially crafted document can a… Poi after 4.1.0 Fix from $1,6002019-10-23 HIGH 8.1 CVE-2019-10466 An XML external entities (XXE) vulnerability in Jenkins 360 FireLine Plugin allows attackers with Overall/Read access to have Jenkins resolve externa… 360 Fireline after 1.7.2 Fix from $1,9502019-10-23 MEDIUM 6.5 CVE-2019-14276 WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body. Xnat Patch available Fix from $1,6002019-10-23 HIGH 8.8 CVE-2019-1060EPSS 14% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-10-10 MEDIUM 6.5 CVE-2019-12711 A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Editio… Unified Communications Manager Mitigation only Fix from $1,6002019-10-02 HIGH 7.1 CVE-2019-16188 HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations. In particular, an attacker can send a sp… Appscan Source 9.03.13+ Fix from $1,9502019-09-25 HIGH 8.8 CVE-2019-16174 An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute … Limesurvey 3.17.14+ Fix from $1,9502019-09-09 HIGH 7.5 CVE-2019-6179 An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity I… Xclarity Administrator 2.5.0 / 6.1.0+ Fix from $1,9502019-09-03 HIGH 7.5 CVE-2019-13608 KEVEPSS 30% Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks. Storefront Server 3.0.8000 / 3.12.4000+ Fix from $1,9502019-08-29 MEDIUM 6.5 CVE-2019-15641 xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks. By default, only root, admin, and sysadm can access xmlrpc.cgi. Webmin after 1.930 Fix from $1,6002019-08-26 HIGH 8.1 CVE-2019-15637EPSS 14% Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This… Tableau Server after 2019.2.2 Fix from $1,9502019-08-26 HIGH 8.2 CVE-2019-4513 IBM Security Access Manager for Enterprise Single Sign-On 8.2.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML da… Security Access Manager For Enterprise Single Sign On Mitigation only Fix from $1,9502019-08-26 HIGH 7.5 CVE-2019-14258 The XML-RPC subsystem in Zenoss 2.5.3 allows XXE attacks that lead to unauthenticated information disclosure via port 9988. Zenoss No fix yet Fix from $1,9502019-08-21 HIGH 8.2 CVE-2019-4340 IBM Security Guardium Big Data Intelligence 4.0 (SonarG) is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A r… Security Guardium Big Data Intelligence Mitigation only Fix from $1,9502019-08-20 HIGH 8.2 CVE-2019-4424 IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, and 19.0.0.2 is vulnerable to an XML External Entity Injection (XXE) attack … Business Automation Workflow after 19.0.0.2 Fix from $1,9502019-08-20 HIGH 8.2 CVE-2019-4433 IBM InfoSphere Global Name Management 5.0 and 6.0 and IBM InfoSphere Identity Insight 8.1 and 9.0 is vulnerable to an XML External Entity Injection (… Infosphere Global Name Management Mitigation only Fix from $1,9502019-08-20 HIGH 8.2 CVE-2019-4419 IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… Intelligent Operations Center after 5.2.1.1 Fix from $1,9502019-08-20 MEDIUM 5.5 CVE-2019-1187 A denial of service vulnerability exists when the XmlLite runtime (XmlLite.dll) improperly parses XML input. An attacker who successfully exploited t… Windows 10 Patch available Fix from $1,6002019-08-14