Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2017-9362
ManageEngine ServiceDesk Plus before 9312 contains an XML injection at add Configuration items CMDB API.
Manageengine Servicedesk Plus
9.3+
MEDIUM 5.9
CVE-2019-8997
An XML External Entity Injection (XXE) vulnerability in the Management System (console) of BlackBerry AtHoc versions earlier than 7.6 HF-567 could al…
Athoc
7.6_hf-567+
HIGH 7.5
CVE-2019-9761
An XXE issue was discovered in PHPSHE 1.7, which can be used to read any file in the system or scan the internal network without authentication. This…
Phpshe
No fix yet
MEDIUM 6.5
CVE-2019-0277
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer w…
Hana Extended Application Services
Mitigation only
CRITICAL 9.1
CVE-2019-5918
Nablarch 5 (5, and 5u1 to 5u13) allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Nablarch
Mitigation only
MEDIUM 5.3
CVE-2019-9658
Checkstyle before 8.18 loads external DTDs by default.
Debian Linux
8.18+
CRITICAL 9.1
CVE-2018-1727
IBM InfoSphere Information Server 9.1, 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A…
Infosphere Information Server
Mitigation only
HIGH 8.1
CVE-2019-7722
PMD 5.8.1 and earlier processes XML external entities in ruleset files it parses as part of the analysis process, allowing attackers tampering it (ei…
Pmd
after 5.8.1
CRITICAL 9.1
CVE-2019-1003015
An XML external entity processing vulnerability exists in Jenkins Job Import Plugin 2.1 and earlier in src/main/java/org/jenkins/ci/plugins/jobimport…
Job Import
after 2.1
MEDIUM 5.3
CVE-2018-1801
IBM App Connect V11.0.0.0 through V11.0.0.1, IBM Integration Bus V10.0.0.0 through V10.0.0.13, IBM Integration Bus V9.0.0.0 through V9.0.0.10, and We…
App Connect
after 11.0.0.1
HIGH 7.1
CVE-2018-1970
IBM Security Identity Manager 7.0.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could e…
Security Access Manager
after 7.0.1.10
HIGH 8.6
CVE-2018-19858
PrinceXML, versions 10 and below, is vulnerable to XXE due to the lack of protection against external entities. If an attacker passes HTML referencin…
Princexml
after 10.0
CRITICAL 9.8
CVE-2019-3773
Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity Injection (…
Spring Web Services
after 8.1.0
CRITICAL 9.8
CVE-2019-3774
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML…
Spring Batch
after 4.0.1
CRITICAL 9.8
CVE-2019-3772
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were s…
Spring Integration
after 5.1.1
MEDIUM 6.5
CVE-2018-20233
The Upload add-on resource in Atlassian Universal Plugin Manager before version 2.22.14 allows remote attackers who have system administrator privile…
Universal Plugin Manager
2.22.14+
HIGH 7.1
CVE-2018-2019
IBM Security Identity Manager 6.0.0 Virtual Appliance is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…
Security Identity Manager
Patch available
HIGH 7.5
CVE-2018-20733
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
Web Infrastructure Platform
9.4+
CRITICAL 10.0
CVE-2015-9280
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
Mailenable
8.60+
HIGH 8.8
CVE-2018-16166
LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Logontracer
after 1.2.0
CRITICAL 9.8
CVE-2019-5748
In Traccar Server version 4.2, protocol/SpotProtocolDecoder.java might allow XXE attacks.
Server
Patch available
CRITICAL 9.8
CVE-2018-11788EPSS 7%
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy folder. The …
Karaf
4.1.7+
CRITICAL 9.8
CVE-2019-5312
An issue was discovered in weixin-java-tools v3.3.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file. NOTE: th…
Wxjava
3.4.0+
CRITICAL 9.8
CVE-2018-20664EPSS 8%
Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.
Manageengine Adselfservice Plus
Mitigation only
MEDIUM 6.5
CVE-2018-19371EPSS 6%
The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.
Web Content Manager
No fix yet
CRITICAL 9.8
CVE-2018-14720EPSS 8%
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…
Debian Linux
2.6.7.2 / 2.7.9.5+
HIGH 8.8
CVE-2018-1000889
Logisim Evolution version 2.14.3 and earlier contains an XML External Entity (XXE) vulnerability in Circuit file loading functionality (loadXmlFrom i…
Logisim Evolution
after 2.14.3
HIGH 7.5
CVE-2018-7837
An Improper Restriction of XML External Entity Reference ('XXE') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that co…
Iiot Monior
Mitigation only
CRITICAL 9.8
CVE-2018-20433
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Debian Linux
Patch available
CRITICAL 9.8
CVE-2018-20318
An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.
Wxjava
No fix yet