Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.1 CVE-2018-1905 IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re… Websphere Application Server after 9.0.0.9 Fix from $1,9502018-11-26 HIGH 8.6 CVE-2018-19244 An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file fr… Charles No fix yet Fix from $1,9502018-11-13 HIGH 7.3 CVE-2018-15444 A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read … Energy Management Suite Software No fix yet Fix from $1,9502018-11-08 HIGH 7.2 CVE-2018-17186 An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file writ… Syncope after 2.1.2 Fix from $1,9502018-11-06 HIGH 7.5 CVE-2018-18980EPSS 25% An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the … Manageengine Network Configuration Manager 12.3.214+ Fix from $1,9502018-11-06 HIGH 7.1 CVE-2018-1835 IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote… Daeja Viewone Mitigation only Fix from $1,9502018-11-02 HIGH 7.1 CVE-2018-1846 IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack whe… Rational Engineering Lifecycle Manager after 6.0.6 Fix from $1,9502018-11-02 HIGH 7.5 CVE-2018-17912 An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure. Case Suite after 3.10 Fix from $1,9502018-11-02 HIGH 7.5 CVE-2018-18737 An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF. Douchat No fix yet Fix from $1,9502018-10-29 HIGH 7.5 CVE-2018-18659 An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management… Udp Patch available Fix from $1,9502018-10-26 HIGH 7.1 CVE-2018-1747 IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r… Security Key Lifecycle Manager after 3.0.0.1 Fix from $1,9502018-10-15 HIGH 7.1 CVE-2018-1844 IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker… Filenet Content Manager Patch available Fix from $1,9502018-10-12 CRITICAL 9.8 CVE-2018-12544 In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against X… Vert.x Patch available Fix from $2,3002018-10-10 MEDIUM 5.5 CVE-2018-8527EPSS 23% An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a refere… Sql Server Management Studio Patch available Fix from $1,6002018-10-10 MEDIUM 5.5 CVE-2018-8532EPSS 23% An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refer… Sql Server Management Studio Patch available Fix from $1,6002018-10-10 MEDIUM 5.5 CVE-2018-8533EPSS 23% An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refer… Sql Server Management Studio Patch available Fix from $1,6002018-10-10 HIGH 8.8 CVE-2018-8494EPSS 22% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502018-10-10 HIGH 7.5 CVE-2018-11796EPSS 7% In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac… Tika after 1.19 Fix from $1,9502018-10-09 HIGH 8.8 CVE-2018-10614 An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files. Levistudiou Mitigation only Fix from $1,9502018-10-09 MEDIUM 5.3 CVE-2018-17889 In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParse… Pi Studio after 4.2.34 Fix from $1,6002018-10-08 MEDIUM 5.7 CVE-2018-0414 A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certai… Secure Access Control Server Solution Engine 5.8+ Fix from $1,6002018-10-05 HIGH 8.1 CVE-2018-12471 A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing … Subscription Management Tool 3.0.37+ Fix from $1,9502018-10-04 HIGH 7.1 CVE-2018-1702 IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) at… Platform Symphony Mitigation only Fix from $1,9502018-09-28 CRITICAL 9.8 CVE-2018-17411 An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20. Data Quality Suite No fix yet Fix from $2,3002018-09-26 CRITICAL 9.8 CVE-2018-15531EPSS 28% JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. Javamelody 1.74.0+ Fix from $2,3002018-09-26 HIGH 7.1 CVE-2018-1669 IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as we… Datapower Gateway after 7.7.1.2 Fix from $1,9502018-09-25 HIGH 7.1 CVE-2018-1588 IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Inject… Rational Engineering Lifecycle Manager after 6.0.6 Fix from $1,9502018-09-25 HIGH 7.1 CVE-2018-1607 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when … Rational Engineering Lifecycle Manager after 6.0.6 Fix from $1,9502018-09-25 HIGH 8.8 CVE-2018-12243 The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML … Messaging Gateway 10.6.6+ Fix from $1,9502018-09-19 HIGH 7.5 CVE-2018-11761EPSS 10% In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln… Tika after 1.18 Fix from $1,9502018-09-19