Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.9
CVE-2018-17247
Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw…
Elasticsearch
Mitigation only
CRITICAL 9.1
CVE-2018-1000844
Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JA…
Retrofit
2.5.0+
CRITICAL 10.0
CVE-2018-1000825
FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of …
Freecol
after 2018-08-22
CRITICAL 9.0
CVE-2018-1000828
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can res…
Frostwire
Mitigation only
CRITICAL 9.0
CVE-2018-1000829
Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Dis…
Anyplace
Mitigation only
CRITICAL 10.0
CVE-2018-1000830
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data,…
Xr3player
after 3.124
CRITICAL 10.0
CVE-2018-1000831
K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential d…
K 9 Mail
after 5.600
CRITICAL 9.0
CVE-2018-1000834
runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can re…
Runelite
after 1.4.23
CRITICAL 10.0
CVE-2018-1000835
KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidenti…
Keepass Dx
Mitigation only
CRITICAL 9.0
CVE-2018-1000836
bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can res…
Bw Calendar Engine
after 3.12.0
CRITICAL 10.0
CVE-2018-1000837
UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confident…
Uml Designer
after 8.0.0
CRITICAL 10.0
CVE-2018-1000838
autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential …
Autopsy
after 4.9.0
MEDIUM 6.5
CVE-2018-1000840
Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in …
Processing
after 3.4
CRITICAL 10.0
CVE-2018-1000820
neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in…
Awesome Procedures On Cyper
Patch available
CRITICAL 10.0
CVE-2018-1000821
MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure …
Micromathematics
2.17.3+
CRITICAL 10.0
CVE-2018-1000822
codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure o…
Fess
12.2.3+
CRITICAL 10.0
CVE-2018-1000823
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confiden…
Exist
5.0.0+
MEDIUM 6.5
CVE-2018-20298
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash…
S3 Browser
8.1.5+
HIGH 7.5
CVE-2018-20157
The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t…
Openrefine
after 3.1
CRITICAL 9.1
CVE-2018-1821EPSS 16%
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat…
Operational Decision Manager
8.6.0.3 / 8.7.1.2+
HIGH 7.1
CVE-2018-2492
SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in ver…
Netweaver Application Server Java
Mitigation only
CRITICAL 9.8
CVE-2018-20059
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.
Pippo
No fix yet
CRITICAL 9.1
CVE-2018-15805
Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files…
Prizmdoc
13.5+
HIGH 7.5
CVE-2018-20000
Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/ser…
Bw Webdav
4.0.3+
HIGH 8.1
CVE-2018-7063
In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been di…
Clearpass Policy Manager
6.6.10 / 6.7.3+
HIGH 7.1
CVE-2018-1424
IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack…
Marketing Platform
Mitigation only
HIGH 7.1
CVE-2018-1920
IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke…
Marketing Platform
Mitigation only
CRITICAL 9.1
CVE-2018-15362
XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0
Cimplicity
Mitigation only
CRITICAL 9.1
CVE-2018-16792
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to ex…
Sftp\/scp Server
after 2018-09-10
HIGH 7.1
CVE-2018-1730
IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…
Qradar Security Information And Event Manager
after 7.3.1