Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
MEDIUM 5.9 CVE-2018-17247 Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external netw… Elasticsearch Mitigation only Fix from $1,6002018-12-20 CRITICAL 9.1 CVE-2018-1000844 Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JA… Retrofit 2.5.0+ Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000825 FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of … Freecol after 2018-08-22 Fix from $2,3002018-12-20 CRITICAL 9.0 CVE-2018-1000828 FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can res… Frostwire Mitigation only Fix from $2,3002018-12-20 CRITICAL 9.0 CVE-2018-1000829 Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Dis… Anyplace Mitigation only Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000830 XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data,… Xr3player after 3.124 Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000831 K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential d… K 9 Mail after 5.600 Fix from $2,3002018-12-20 CRITICAL 9.0 CVE-2018-1000834 runelite version <= runelite-parent-1.4.23 contains a XML External Entity (XXE) vulnerability in Man in the middle runscape services call that can re… Runelite after 1.4.23 Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000835 KeePassDX version <= 2.5.0.0beta17 contains a XML External Entity (XXE) vulnerability in kdbx file parser that can result in Disclosure of confidenti… Keepass Dx Mitigation only Fix from $2,3002018-12-20 CRITICAL 9.0 CVE-2018-1000836 bw-calendar-engine version <= bw-calendar-engine-3.12.0 contains a XML External Entity (XXE) vulnerability in IscheduleClient XML Parser that can res… Bw Calendar Engine after 3.12.0 Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000837 UML Designer version <= 8.0.0 contains a XML External Entity (XXE) vulnerability in XML parser for plugins that can result in Disclosure of confident… Uml Designer after 8.0.0 Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000838 autopsy version <= 4.9.0 contains a XML External Entity (XXE) vulnerability in CaseMetadata XML Parser that can result in Disclosure of confidential … Autopsy after 4.9.0 Fix from $2,3002018-12-20 MEDIUM 6.5 CVE-2018-1000840 Processing Foundation Processing version 3.4 and earlier contains a XML External Entity (XXE) vulnerability in loadXML() function that can result in … Processing after 3.4 Fix from $1,6002018-12-20 CRITICAL 10.0 CVE-2018-1000820 neo4j-contrib neo4j-apoc-procedures version before commit 45bc09c contains a XML External Entity (XXE) vulnerability in XML Parser that can result in… Awesome Procedures On Cyper Patch available Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000821 MicroMathematics version before commit 5c05ac8 contains a XML External Entity (XXE) vulnerability in SMathStudio files that can result in Disclosure … Micromathematics 2.17.3+ Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000822 codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure o… Fess 12.2.3+ Fix from $2,3002018-12-20 CRITICAL 10.0 CVE-2018-1000823 exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confiden… Exist 5.0.0+ Fix from $2,3002018-12-20 MEDIUM 6.5 CVE-2018-20298 S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash… S3 Browser 8.1.5+ Fix from $1,6002018-12-19 HIGH 7.5 CVE-2018-20157 The data import functionality in OpenRefine through 3.1 allows an XML External Entity (XXE) attack through a crafted (zip) file, allowing attackers t… Openrefine after 3.1 Fix from $1,9502018-12-15 CRITICAL 9.1 CVE-2018-1821EPSS 16% IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML dat… Operational Decision Manager 8.6.0.3 / 8.7.1.2+ Fix from $2,3002018-12-13 HIGH 7.1 CVE-2018-2492 SAML 2.0 functionality in SAP NetWeaver AS Java, does not sufficiently validate XML documents received from an untrusted source. This is fixed in ver… Netweaver Application Server Java Mitigation only Fix from $1,9502018-12-11 CRITICAL 9.8 CVE-2018-20059 jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE. Pippo No fix yet Fix from $2,3002018-12-11 CRITICAL 9.1 CVE-2018-15805 Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files… Prizmdoc 13.5+ Fix from $2,3002018-12-10 HIGH 7.5 CVE-2018-20000 Apereo Bedework bw-webdav before 4.0.3 allows XXE attacks, as demonstrated by an invite-reply document that reads a local file, related to webdav/ser… Bw Webdav 4.0.3+ Fix from $1,9502018-12-10 HIGH 8.1 CVE-2018-7063 In Aruba ClearPass, disabled API admins can still perform read/write operations. In certain circumstances, API admins in ClearPass which have been di… Clearpass Policy Manager 6.6.10 / 6.7.3+ Fix from $1,9502018-12-07 HIGH 7.1 CVE-2018-1424 IBM Marketing Platform 9.1.0, 9.1.2, and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attack… Marketing Platform Mitigation only Fix from $1,9502018-12-07 HIGH 7.1 CVE-2018-1920 IBM Marketing Platform 9.1.0, 9.1.2 and 10.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacke… Marketing Platform Mitigation only Fix from $1,9502018-12-07 CRITICAL 9.1 CVE-2018-15362 XXE in GE Proficy Cimplicity GDS versions 9.0 R2, 9.5, 10.0 Cimplicity Mitigation only Fix from $2,3002018-12-07 CRITICAL 9.1 CVE-2018-16792 SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to ex… Sftp\/scp Server after 2018-09-10 Fix from $2,3002018-12-05 HIGH 7.1 CVE-2018-1730 IBM QRadar SIEM 7.2 and 7.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t… Qradar Security Information And Event Manager after 7.3.1 Fix from $1,9502018-12-05