Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.8 CVE-2017-9362 ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API. Manageengine Servicedesk Plus 9.3+ Fix from $1,9502019-03-25 MEDIUM 5.9 CVE-2019-8997 An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could al… Athoc 7.6_hf-567+ Fix from $1,6002019-03-21 HIGH 7.5 CVE-2019-9761 An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This… Phpshe No fix yet Fix from $1,9502019-03-14 MEDIUM 6.5 CVE-2019-0277 SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer w… Hana Extended Application Services Mitigation only Fix from $1,6002019-03-12 CRITICAL 9.1 CVE-2019-5918 Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Nablarch Mitigation only Fix from $2,3002019-03-12 MEDIUM 5.3 CVE-2019-9658 Checkstyle before 8.18 loads external DTDs by default. Debian Linux 8.18+ Fix from $1,6002019-03-11 CRITICAL 9.1 CVE-2018-1727 IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A… Infosphere Information Server Mitigation only Fix from $2,3002019-02-15 HIGH 8.1 CVE-2019-7722 PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (ei… Pmd after 5.8.1 Fix from $1,9502019-02-11 CRITICAL 9.1 CVE-2019-1003015 An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport… Job Import after 2.1 Fix from $2,3002019-02-06 MEDIUM 5.3 CVE-2018-1801 IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and We… App Connect after 11.0.0.1 Fix from $1,6002019-02-04 HIGH 7.1 CVE-2018-1970 IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e… Security Access Manager after 7.0.1.10 Fix from $1,9502019-02-04 HIGH 8.6 CVE-2018-19858 PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencin… Princexml after 10.0 Fix from $1,9502019-01-30 CRITICAL 9.8 CVE-2019-3773 Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (… Spring Web Services after 8.1.0 Fix from $2,3002019-01-18 CRITICAL 9.8 CVE-2019-3774 Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML… Spring Batch after 4.0.1 Fix from $2,3002019-01-18 CRITICAL 9.8 CVE-2019-3772 Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were s… Spring Integration after 5.1.1 Fix from $2,3002019-01-18 MEDIUM 6.5 CVE-2018-20233 The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privile… Universal Plugin Manager 2.22.14+ Fix from $1,6002019-01-18 HIGH 7.1 CVE-2018-2019 IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot… Security Identity Manager Patch available Fix from $1,9502019-01-18 HIGH 7.5 CVE-2018-20733 BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. Web Infrastructure Platform 9.4+ Fix from $1,9502019-01-17 CRITICAL 10.0 CVE-2015-9280 MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter. Mailenable 8.60+ Fix from $2,3002019-01-16 HIGH 8.8 CVE-2018-16166 LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Logontracer after 1.2.0 Fix from $1,9502019-01-09 CRITICAL 9.8 CVE-2019-5748 In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks. Server Patch available Fix from $2,3002019-01-09 CRITICAL 9.8 CVE-2018-11788EPSS 7% Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The … Karaf 4.1.7+ Fix from $2,3002019-01-07 CRITICAL 9.8 CVE-2019-5312 An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: th… Wxjava 3.4.0+ Fix from $2,3002019-01-04 CRITICAL 9.8 CVE-2018-20664EPSS 8% Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license. Manageengine Adselfservice Plus Mitigation only Fix from $2,3002019-01-03 MEDIUM 6.5 CVE-2018-19371EPSS 6% The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system. Web Content Manager No fix yet Fix from $1,6002019-01-02 CRITICAL 9.8 CVE-2018-14720EPSS 8% FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci… Debian Linux 2.6.7.2 / 2.7.9.5+ Fix from $2,3002019-01-02 HIGH 8.8 CVE-2018-1000889 Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom i… Logisim Evolution after 2.14.3 Fix from $1,9502018-12-28 HIGH 7.5 CVE-2018-7837 An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that co… Iiot Monior Mitigation only Fix from $1,9502018-12-24 CRITICAL 9.8 CVE-2018-20433 c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization. Debian Linux Patch available Fix from $2,3002018-12-24 CRITICAL 9.8 CVE-2018-20318 An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. Wxjava No fix yet Fix from $2,3002018-12-21