Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2019-12154
XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced r…
Pdfreactor
10.1.10722+
HIGH 7.5
CVE-2019-10337
An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the inp…
Token Macro
after 2.7
HIGH 7.5
CVE-2019-3722
Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnera…
Emc Openmanage Server Administrator
Mitigation only
HIGH 8.1
CVE-2019-10327
An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a tempo…
Pipeline Maven Integration
after 1.7.0
CRITICAL 9.8
CVE-2018-20160
ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XX…
Zimbra Collaboration Suite
8.7.11 / 8.8.9+
CRITICAL 9.8
CVE-2019-9670 KEVEPSS 100%
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr…
Zimbra Collaboration Suite
8.7.11+
HIGH 7.5
CVE-2019-0188EPSS 10%
Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib…
Camel
2.24.0+
CRITICAL 9.8
CVE-2018-8940
ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, a…
Contact Center\
No fix yet
CRITICAL 9.8
CVE-2019-7442EPSS 40%
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacke…
Enterprise Password Vault
after 10.7
HIGH 7.1
CVE-2019-4208
IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at…
Tririga Application Platform
3.5.3.6 / 3.6.0.3+
CRITICAL 9.8
CVE-2018-14485EPSS 16%
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
Blogengine.net
No fix yet
CRITICAL 9.8
CVE-2019-11677EPSS 9%
The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio…
Manageengine Firewall Analyzer
Mitigation only
CRITICAL 9.3
CVE-2019-10309
Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p…
Self Organizing Swarm Modules
Mitigation only
HIGH 7.7
CVE-2018-17169
An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct …
Printeron
after 4.1.4
MEDIUM 6.5
CVE-2018-17289
An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated us…
Front Office Server
No fix yet
HIGH 7.5
CVE-2019-8999
An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain r…
Unified Endpoint Management
after 12.10.1a
CRITICAL 9.8
CVE-2019-0228EPSS 9%
Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac…
Pdfbox
Mitigation only
MEDIUM 6.0
CVE-2019-0284
SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attac…
Hana
Mitigation only
HIGH 8.8
CVE-2019-0790EPSS 16%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0791EPSS 17%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0792EPSS 17%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0793EPSS 17%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 8.8
CVE-2019-0795EPSS 21%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 7.5
CVE-2019-10244
In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service …
Kura
after 4.0.0
HIGH 8.8
CVE-2019-0756EPSS 12%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio…
Windows 10
Patch available
CRITICAL 9.8
CVE-2018-20222
XXE issue in Airsonic before 10.1.2 during parse.
Airsonic
10.1.2+
HIGH 7.1
CVE-2019-4043
IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat…
Sterling B2b Integrator
after 5.2.6.4
MEDIUM 6.5
CVE-2017-18110
The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attacker…
Crowd
3.0.2+
HIGH 8.7
CVE-2017-18111
The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version …
Application Links
5.0.10 / 5.1.3+
HIGH 7.1
CVE-2019-3481
Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7.
Arcsight Logger
6.7+