Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2019-1057
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exp…
Windows 10
Patch available
MEDIUM 5.4
CVE-2019-0340
The XML parser, which is being used by SAP Enable Now, before version 1902, has not been hardened correctly, leading to Missing XML Validation vulner…
Enable Now
1902+
HIGH 8.1
CVE-2019-14693
Zoho ManageEngine AssetExplorer 6.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing license XML data. A remote attac…
Manageengine Assetexplorer
Mitigation only
HIGH 7.5
CVE-2019-13176
An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affe…
3cx
No fix yet
HIGH 7.5
CVE-2018-14383
The Transition Technologies "The Scheduler" app 5.1.3 for Jira allows XXE due to a weakly configured/parameterized XML parser. It was fixed in the ve…
The Scheduler
Mitigation only
MEDIUM 6.3
CVE-2017-18438
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
Cpanel
56.0.49 / 58.0.49+
HIGH 7.1
CVE-2019-4062
IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A re…
I2 Intelligent Analysis Platform
after 9.1.1
HIGH 7.1
CVE-2019-4456
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…
Daeja Viewone
after 5.0.6
HIGH 7.2
CVE-2019-10264
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. With a valid administrator account, the "Move / Import / Export Users" screen ha…
Cloud Backup Suite
8.1.1.50+
HIGH 7.5
CVE-2019-10266EPSS 13%
An issue was discovered in Ahsay Cloud Backup Suite before 8.1.1.50. When sending an out-of-bounds XML document to a URL, it is possible to read the …
Cloud Backup Suite
8.1.1.50+
CRITICAL 9.8
CVE-2019-13990EPSS 16%
initDocumentParser in xml/XMLSchedulingDataProcessor.java in Terracotta Quartz Scheduler through 2.3.0 allows XXE attacks via a job description.
Tomee
2.3.2+
MEDIUM 5.5
CVE-2019-10976
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized w…
Electric Fr Configurator2 Firmware
1.16s+
MEDIUM 6.5
CVE-2019-1010202
Jeesite 1.2.7 is affected by: XML External Entity (XXE). The impact is: sensitive information disclosure. The component is: convertToModel() function…
Jeesite
No fix yet
HIGH 7.5
CVE-2019-7847
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have an Improper Restriction of XML External Entity Reference ('XXE') vulnerability.…
Campaign
after 18.10.5.8984
CRITICAL 9.8
CVE-2019-1010268EPSS 6%
Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, …
Ladon
after 0.9.40
CRITICAL 9.1
CVE-2019-13625
NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.
Ghidra
9.0.1+
MEDIUM 6.4
CVE-2018-17152
Intersystems Cache 2017.2.2.865.0 allows XXE.
Cache
No fix yet
CRITICAL 9.8
CVE-2019-12924
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.…
Mailenable
6.90 / 7.62+
HIGH 7.5
CVE-2019-13358EPSS 24%
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read files on the underlying operating system. The attacker mus…
Opencats
0.9.4-3+
CRITICAL 9.8
CVE-2015-3907
CodeIgniter Rest Server (aka codeigniter-restserver) 2.7.1 allows XXE attacks.
Codeigniter Restserver
No fix yet
HIGH 8.1
CVE-2019-13031
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific…
Debian Linux
1.9.20+
HIGH 7.5
CVE-2019-9843
In DiffPlug Spotless before 1.20.0 (library and Maven plugin) and before 3.20.0 (Gradle plugin), the XML parser would resolve external entities over …
Gradle
1.20.0 / 3.20.0+
HIGH 7.5
CVE-2018-20843EPSS 7%
In libexpat in Expat before 2.2.7, XML input including XML names that contain a large number of colons could make the XML parser consume a high amoun…
Ubuntu Linux
2.2.7+
HIGH 7.5
CVE-2019-11392
BlogEngine.NET 3.3.7 and earlier allows XXE via an apml file to syndication.axd.
Blogengine.net
after 3.3.7
HIGH 7.5
CVE-2019-10718
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackH…
Blogengine.net
after 3.3.7.0
CRITICAL 9.1
CVE-2019-1903
A vulnerability in Cisco Security Manager could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of servic…
Security Manager
Mitigation only
CRITICAL 9.8
CVE-2018-15506
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remo…
Bubbleupnp
Mitigation only
CRITICAL 9.9
CVE-2018-18406
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerabili…
Securetrack
No fix yet
CRITICAL 9.8
CVE-2018-18471EPSS 8%
/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE vulnerability that can…
Hipserv
No fix yet
HIGH 7.1
CVE-2018-1845
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remo…
Infosphere Information Server
Patch available