Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
CRITICAL 9.1 CVE-2019-12154 XXE in the XML parser library in RealObjects PDFreactor before 10.1.10722 allows attackers to supply malicious XML content in externally referenced r… Pdfreactor 10.1.10722+ Fix from $2,3002019-06-11 HIGH 7.5 CVE-2019-10337 An XML external entities (XXE) vulnerability in Jenkins Token Macro Plugin 2.7 and earlier allowed attackers able to control a the content of the inp… Token Macro after 2.7 Fix from $1,9502019-06-11 HIGH 7.5 CVE-2019-3722 Dell EMC OpenManage Server Administrator (OMSA) versions prior to 9.1.0.3 and prior to 9.2.0.4 contain an XML external entity (XXE) injection vulnera… Emc Openmanage Server Administrator Mitigation only Fix from $1,9502019-06-06 HIGH 8.1 CVE-2019-10327 An XML external entities (XXE) vulnerability in Jenkins Pipeline Maven Integration Plugin 1.7.0 and earlier allowed attackers able to control a tempo… Pipeline Maven Integration after 1.7.0 Fix from $1,9502019-05-31 CRITICAL 9.8 CVE-2018-20160 ZxChat (aka ZeXtras Chat), as used for zimbra-chat and zimbra-talk in Synacor Zimbra Collaboration Suite 8.7 and 8.8 and in other products, allows XX… Zimbra Collaboration Suite 8.7.11 / 8.8.9+ Fix from $2,3002019-05-29 CRITICAL 9.8 CVE-2019-9670 KEVEPSS 100% mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstr… Zimbra Collaboration Suite 8.7.11+ Fix from $2,3002019-05-29 HIGH 7.5 CVE-2019-0188EPSS 10% Apache Camel prior to 2.24.0 contains an XML external entity injection (XXE) vulnerability (CWE-611) due to using an outdated vulnerable JSON-lib lib… Camel 2.24.0+ Fix from $1,9502019-05-28 CRITICAL 9.8 CVE-2018-8940 ClientServiceConfigController.cs in Enghouse Cloud Contact Center Platform 7.2.5 has functionality for loading external XML files and parsing them, a… Contact Center\ No fix yet Fix from $2,3002019-05-14 CRITICAL 9.8 CVE-2019-7442EPSS 40% An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remote attacke… Enterprise Password Vault after 10.7 Fix from $2,3002019-05-08 HIGH 7.1 CVE-2019-4208 IBM TRIRIGA Application Platform 3.5.3 and 3.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote at… Tririga Application Platform 3.5.3.6 / 3.6.0.3+ Fix from $1,9502019-05-07 CRITICAL 9.8 CVE-2018-14485EPSS 16% BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd. Blogengine.net No fix yet Fix from $2,3002019-05-07 CRITICAL 9.8 CVE-2019-11677EPSS 9% The Custom Report import function in Zoho ManageEngine Firewall Analyzer before 12.3 Build 123224 is vulnerable to XML External Entity (XXE) Injectio… Manageengine Firewall Analyzer Mitigation only Fix from $2,3002019-05-02 CRITICAL 9.3 CVE-2019-10309 Jenkins Self-Organizing Swarm Plug-in Modules Plugin clients that use UDP broadcasts to discover Jenkins masters do not prevent XML External Entity p… Self Organizing Swarm Modules Mitigation only Fix from $2,3002019-04-30 HIGH 7.7 CVE-2018-17169 An XML external entity (XXE) vulnerability in PrinterOn version 4.1.4 and lower allows remote authenticated users to read arbitrary files or conduct … Printeron after 4.1.4 Fix from $1,9502019-04-23 MEDIUM 6.5 CVE-2018-17289 An XML external entity (XXE) vulnerability in Kofax Front Office Server Administration Console version 4.1.1.11.0.5212 allows remote authenticated us… Front Office Server No fix yet Fix from $1,6002019-04-18 HIGH 7.5 CVE-2019-8999 An XML External Entity vulnerability in the UEM Core of BlackBerry UEM version(s) earlier than 12.10.1a could allow an attacker to potentially gain r… Unified Endpoint Management after 12.10.1a Fix from $1,9502019-04-18 CRITICAL 9.8 CVE-2019-0228EPSS 9% Apache PDFBox 2.0.14 does not properly initialize the XML parser, which allows context-dependent attackers to conduct XML External Entity (XXE) attac… Pdfbox Mitigation only Fix from $2,3002019-04-17 MEDIUM 6.0 CVE-2019-0284 SLD Registration in SAP HANA (fixed in versions 1.0, 2.0) does not sufficiently validate an XML document accepted from an untrusted source. The attac… Hana Mitigation only Fix from $1,6002019-04-10 HIGH 8.8 CVE-2019-0790EPSS 16% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-0791EPSS 17% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-0792EPSS 17% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-0793EPSS 17% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-0795EPSS 21% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 HIGH 7.5 CVE-2019-10244 In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service … Kura after 4.0.0 Fix from $1,9502019-04-09 HIGH 8.8 CVE-2019-0756EPSS 12% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502019-04-09 CRITICAL 9.8 CVE-2018-20222 XXE issue in Airsonic before 10.1.2 during parse. Airsonic 10.1.2+ Fix from $2,3002019-04-04 HIGH 7.1 CVE-2019-4043 IBM Sterling B2B Integrator Standard Edition 5.2.0 snf 6.0.0.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML dat… Sterling B2b Integrator after 5.2.6.4 Fix from $1,9502019-04-02 MEDIUM 6.5 CVE-2017-18110 The administration backup restore resource in Atlassian Crowd before version 3.0.2 and from version 3.1.0 before version 3.1.1 allows remote attacker… Crowd 3.0.2+ Fix from $1,6002019-03-29 HIGH 8.7 CVE-2017-18111 The OAuthHelper in Atlassian Application Links before version 5.0.10, from version 5.1.0 before version 5.1.3, and from version 5.2.0 before version … Application Links 5.0.10 / 5.1.3+ Fix from $1,9502019-03-29 HIGH 7.1 CVE-2019-3481 Mitigates a XML External Entity Parsing issue in ArcSight Logger versions prior to 6.7. Arcsight Logger 6.7+ Fix from $1,9502019-03-25