Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.2 CVE-2018-12585 An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service. Ua .net Legacy after 1.3.343 Fix from $1,9502018-09-14 HIGH 8.8 CVE-2018-8420EPSS 49% A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Executio… Windows 10 Patch available Fix from $1,9502018-09-13 CRITICAL 9.8 CVE-2018-16521 An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0. Html Form Entry Patch available Fix from $2,3002018-09-05 HIGH 7.5 CVE-2018-16303 PDF-XChange Editor through 7.0.326.1 allows remote attackers to cause a denial of service (resource consumption) via a crafted x:xmpmeta structure, a… Pdf Xchange Editor after 7.0.326.1 Fix from $1,9502018-09-01 HIGH 7.5 CVE-2018-13823 An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allo… Project Portfolio Management after 14.3 Fix from $1,9502018-08-30 CRITICAL 9.1 CVE-2018-13826 An XML external entity vulnerability in the XOG functionality, in CA PPM 14.3 and below, 14.4, 15.1, 15.2 CP5 and below, and 15.3 CP2 and below, allo… Project Portfolio Management after 14.3 Fix from $2,3002018-08-30 HIGH 7.5 CVE-2017-17762 XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XM… Episerver after 7 Fix from $1,9502018-08-29 HIGH 8.1 CVE-2018-11758 This affects Apache Cayenne 4.1.M1, 3.2.M1, 4.0.M2 to 4.0.M5, 4.0.B1, 4.0.B2, 4.0.RC1, 3.1, 3.1.1, 3.1.2. CayenneModeler is a desktop GUI tool shippe… Cayenne after 3.1.0 Fix from $1,9502018-08-22 CRITICAL 10.0 CVE-2018-1000652 JabRef version <=4.3.1 contains a XML External Entity (XXE) vulnerability in MsBibImporter XML Parser that can result in disclosure of confidential d… Jabref after 4.3.1 Fix from $2,3002018-08-20 CRITICAL 10.0 CVE-2018-1000651 Stroom version <5.4.5 contains a XML External Entity (XXE) vulnerability in XML Parser that can result in disclosure of confidential data, denial of … Stroom 5.4.5+ Fix from $2,3002018-08-20 CRITICAL 10.0 CVE-2018-1000644 Eclipse RDF4j version < 2.4.0 Milestone 2 contains a XML External Entity (XXE) vulnerability in RDF4j XML parser parsing RDF files that can result in… Rdf4j 2.4.0+ Fix from $2,3002018-08-20 CRITICAL 9.6 CVE-2018-1000639 LatexDraw version <=4.0 contains a XML External Entity (XXE) vulnerability in SVG parsing functionality that can result in disclosure of data, server… Latexdraw after 3.3.9 Fix from $2,3002018-08-20 CRITICAL 9.8 CVE-2018-13417EPSS 21% In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack… Bittorrent Client No fix yet Fix from $2,3002018-08-13 CRITICAL 9.8 CVE-2018-13415EPSS 32% In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.… Media Server No fix yet Fix from $2,3002018-08-13 HIGH 8.1 CVE-2018-11048 Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XM… Emc Data Protection Advisor Mitigation only Fix from $1,9502018-08-10 HIGH 7.5 CVE-2018-12408 The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO… Activematrix Businessworks after 5.13.0 Fix from $1,9502018-08-08 HIGH 8.8 CVE-2016-8526EPSS 10% Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to… Airwave 8.2.3.1+ Fix from $1,9502018-08-06 CRITICAL 9.1 CVE-2018-14473 OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sendi… Ocsinventory Ng No fix yet Fix from $2,3002018-08-04 CRITICAL 9.8 CVE-2018-13416EPSS 20% In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) at… Universal Media Server No fix yet Fix from $2,3002018-08-03 HIGH 7.5 CVE-2017-8316 IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code… Intellij Idea 2017.2.2+ Fix from $1,9502018-08-03 HIGH 8.1 CVE-2017-16349 An exploitable XML external entity vulnerability exists in the reporting functionality of SAP BPC. A specially crafted XML request can cause an XML e… Business Planning And Consolidation Mitigation only Fix from $1,9502018-08-02 CRITICAL 9.4 CVE-2018-3881 An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a spe… Focalscope No fix yet Fix from $2,3002018-08-01 CRITICAL 9.8 CVE-2018-8027EPSS 6% Apache Camel 2.20.0 to 2.20.3 and 2.21.0 Core is vulnerable to XXE in XSD validation processor. Camel after 2.20.3 Fix from $2,3002018-07-31 CRITICAL 9.8 CVE-2017-7464 It was found that the JAXP implementation used in JBoss EAP 7.0 for SAX and DOM parsing is vulnerable to certain XXE flaws. An attacker could use thi… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002018-07-27 MEDIUM 6.5 CVE-2017-7545 It was discovered that the XmlUtils class in jbpmmigration 6.5 performed expansion of external parameter entities while parsing XML files. A remote a… Decision Manager Patch available Fix from $1,6002018-07-26 CRITICAL 9.8 CVE-2018-10600 SEL AcSELerator Architect version 2.2.24.0 and prior allows unsanitized input to be passed to the XML parser, which may allow disclosure and retrieva… Acselerator Architect after 2.2.24.0 Fix from $2,3002018-07-24 HIGH 8.8 CVE-2014-2296 XML external entity (XXE) vulnerability in java/org/jasig/cas/util/SamlUtils.java in Jasig CAS server before 3.4.12.1 and 3.5.x before 3.5.2.1, when … Cas Server 3.4.12.1 / 3.5.2.1+ Fix from $1,9502018-07-20 CRITICAL 9.8 CVE-2018-14065 XMLReader.php in PHPOffice Common before 0.2.9 allows XXE. Common 0.2.9+ Fix from $2,3002018-07-15 HIGH 7.8 CVE-2016-9487 EpubCheck 4.0.1 does not properly restrict resolving external entities when parsing XML in EPUB files during validation. An attacker who supplies a s… Epubcheck Mitigation only Fix from $1,9502018-07-13 CRITICAL 9.8 CVE-2018-12463EPSS 14% An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to… Fortify Software Security Center No fix yet Fix from $2,3002018-07-12