Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.1
CVE-2018-1905
IBM WebSphere Application Server 9.0.0.0 through 9.0.0.9 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A re…
Websphere Application Server
after 9.0.0.9
HIGH 8.6
CVE-2018-19244
An XML External Entity (XXE) vulnerability exists in the Charles 4.2.7 import/export setup option. If a user imports a "Charles Settings.xml" file fr…
Charles
No fix yet
HIGH 7.3
CVE-2018-15444
A vulnerability in the web-based user interface of Cisco Energy Management Suite Software could allow an authenticated, remote attacker to gain read …
Energy Management Suite Software
No fix yet
HIGH 7.2
CVE-2018-17186
An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file writ…
Syncope
after 2.1.2
HIGH 7.5
CVE-2018-18980EPSS 25%
An XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before 12.3.214 via the …
Manageengine Network Configuration Manager
12.3.214+
HIGH 7.1
CVE-2018-1835
IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote…
Daeja Viewone
Mitigation only
HIGH 7.1
CVE-2018-1846
IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack whe…
Rational Engineering Lifecycle Manager
after 6.0.6
HIGH 7.5
CVE-2018-17912
An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.
Case Suite
after 3.10
HIGH 7.5
CVE-2018-18737
An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
Douchat
No fix yet
HIGH 7.5
CVE-2018-18659
An issue was discovered in Arcserve Unified Data Protection (UDP) through 6.5 Update 4. There is a DDI-VRT-2018-19 Unauthenticated XXE in /management…
Udp
Patch available
HIGH 7.1
CVE-2018-1747
IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A r…
Security Key Lifecycle Manager
after 3.0.0.1
HIGH 7.1
CVE-2018-1844
IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…
Filenet Content Manager
Patch available
CRITICAL 9.8
CVE-2018-12544
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against X…
Vert.x
Patch available
MEDIUM 5.5
CVE-2018-8527EPSS 23%
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XEL file containing a refere…
Sql Server Management Studio
Patch available
MEDIUM 5.5
CVE-2018-8532EPSS 23%
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious XMLA file containing a refer…
Sql Server Management Studio
Patch available
MEDIUM 5.5
CVE-2018-8533EPSS 23%
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing malicious XML content containing a refer…
Sql Server Management Studio
Patch available
HIGH 8.8
CVE-2018-8494EPSS 22%
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Executio…
Windows 10
Patch available
HIGH 7.5
CVE-2018-11796EPSS 7%
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after eac…
Tika
after 1.19
HIGH 8.8
CVE-2018-10614
An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.
Levistudiou
Mitigation only
MEDIUM 5.3
CVE-2018-17889
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParse…
Pi Studio
after 4.2.34
MEDIUM 5.7
CVE-2018-0414
A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certai…
Secure Access Control Server Solution Engine
5.8+
HIGH 8.1
CVE-2018-12471
A External Entity Reference ('XXE') vulnerability in SUSE Linux SMT allows remote attackers to read data from the server or cause DoS by referencing …
Subscription Management Tool
3.0.37+
HIGH 7.1
CVE-2018-1702
IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) at…
Platform Symphony
Mitigation only
CRITICAL 9.8
CVE-2018-17411
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
Data Quality Suite
No fix yet
CRITICAL 9.8
CVE-2018-15531EPSS 28%
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
Javamelody
1.74.0+
HIGH 7.1
CVE-2018-1669
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as we…
Datapower Gateway
after 7.7.1.2
HIGH 7.1
CVE-2018-1588
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Inject…
Rational Engineering Lifecycle Manager
after 6.0.6
HIGH 7.1
CVE-2018-1607
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to a XML External Entity Injection (XXE) attack when …
Rational Engineering Lifecycle Manager
after 6.0.6
HIGH 8.8
CVE-2018-12243
The Symantec Messaging Gateway product prior to 10.6.6 may be susceptible to a XML external entity (XXE) exploit, which is a type of issue where XML …
Messaging Gateway
10.6.6+
HIGH 7.5
CVE-2018-11761EPSS 10%
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity expansion vuln…
Tika
after 1.18