Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2019-1057 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp… Windows 10 Patch available Fix from $1,9502019-08-14 MEDIUM 5.4 CVE-2019-0340 The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulner… Enable Now 1902+ Fix from $1,6002019-08-14 HIGH 8.1 CVE-2019-14693 Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac… Manageengine Assetexplorer Mitigation only Fix from $1,9502019-08-08 HIGH 7.5 CVE-2019-13176 An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affe… 3cx No fix yet Fix from $1,9502019-08-08 HIGH 7.5 CVE-2018-14383 The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the ve… The Scheduler Mitigation only Fix from $1,9502019-08-07 MEDIUM 6.3 CVE-2017-18438 cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242). Cpanel 56.0.49 / 58.0.49+ Fix from $1,6002019-08-02 HIGH 7.1 CVE-2019-4062 IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re… I2 Intelligent Analysis Platform after 9.1.1 Fix from $1,9502019-07-30 HIGH 7.1 CVE-2019-4456 IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML… Daeja Viewone after 5.0.6 Fix from $1,9502019-07-30 HIGH 7.2 CVE-2019-10264 An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen ha… Cloud Backup Suite 8.1.1.50+ Fix from $1,9502019-07-26 HIGH 7.5 CVE-2019-10266EPSS 13% An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the … Cloud Backup Suite 8.1.1.50+ Fix from $1,9502019-07-26 CRITICAL 9.8 CVE-2019-13990EPSS 16% initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description. Tomee 2.3.2+ Fix from $2,3002019-07-26 MEDIUM 5.5 CVE-2019-10976 Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized w… Electric Fr Configurator2 Firmware 1.16s+ Fix from $1,6002019-07-26 MEDIUM 6.5 CVE-2019-1010202 Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function… Jeesite No fix yet Fix from $1,6002019-07-23 HIGH 7.5 CVE-2019-7847 Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability.… Campaign after 18.10.5.8984 Fix from $1,9502019-07-18 CRITICAL 9.8 CVE-2019-1010268EPSS 6% Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, … Ladon after 0.9.40 Fix from $2,3002019-07-18 CRITICAL 9.1 CVE-2019-13625 NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file. Ghidra 9.0.1+ Fix from $2,3002019-07-17 MEDIUM 6.4 CVE-2018-17152 Intersystems Cache 2017.2.2.865.0 allows XXE. Cache No fix yet Fix from $1,6002019-07-11 CRITICAL 9.8 CVE-2019-12924 MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.… Mailenable 6.90 / 7.62+ Fix from $2,3002019-07-08 HIGH 7.5 CVE-2019-13358EPSS 24% lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus… Opencats 0.9.4-3+ Fix from $1,9502019-07-05 CRITICAL 9.8 CVE-2015-3907 CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks. Codeigniter Restserver No fix yet Fix from $2,3002019-07-03 HIGH 8.1 CVE-2019-13031 LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific… Debian Linux 1.9.20+ Fix from $1,9502019-06-28 HIGH 7.5 CVE-2019-9843 In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over … Gradle 1.20.0 / 3.20.0+ Fix from $1,9502019-06-28 HIGH 7.5 CVE-2018-20843EPSS 7% In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amoun… Ubuntu Linux 2.2.7+ Fix from $1,9502019-06-24 HIGH 7.5 CVE-2019-11392 BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd. Blogengine.net after 3.3.7 Fix from $1,9502019-06-21 HIGH 7.5 CVE-2019-10718 BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackH… Blogengine.net after 3.3.7.0 Fix from $1,9502019-06-21 CRITICAL 9.1 CVE-2019-1903 A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of servic… Security Manager Mitigation only Fix from $2,3002019-06-20 CRITICAL 9.8 CVE-2018-15506 In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remo… Bubbleupnp Mitigation only Fix from $2,3002019-06-19 CRITICAL 9.9 CVE-2018-18406 An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerabili… Securetrack No fix yet Fix from $2,3002019-06-19 CRITICAL 9.8 CVE-2018-18471EPSS 8% /api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can… Hipserv No fix yet Fix from $2,3002019-06-19 HIGH 7.1 CVE-2018-1845 IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo… Infosphere Information Server Patch available Fix from $1,9502019-06-17