Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2018-0765EPSS 8% A denial of service vulnerability exists when .NET and .NET Core improperly process XML documents, aka ".NET and .NET Core Denial of Service Vulnerab… .net Core Patch available Fix from $1,9502018-05-09 HIGH 7.1 CVE-2018-1247EPSS 16% RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External Entity (XXE) vulnerability. This could potentially allo… Authentication Manager after 8.3 Fix from $1,9502018-05-08 CRITICAL 9.8 CVE-2018-1183 In Dell EMC Unisphere for VMAX Virtual Appliance versions prior to 8.4.0.8, Dell EMC Solutions Enabler Virtual Appliance versions prior to 8.4.0.8, D… Emc Smis 4.3.0.1522077968 / 8.4.0.6+ Fix from $2,3002018-04-30 MEDIUM 6.5 CVE-2017-15691EPSS 9% In Apache uimaj prior to 2.10.2, Apache uimaj 3.0.0-xxx prior to 3.0.0-beta, Apache uima-as prior to 2.10.2, Apache uimaFIT prior to 2.4.0, Apache ui… Uimaj 2.2.2 / 2.4.0+ Fix from $1,6002018-04-26 CRITICAL 9.1 CVE-2014-0931 Multiple XML external entity (XXE) vulnerabilities in the (1) CCRC WAN Server / CM Server, (2) Perl CC/CQ integration trigger scripts, (3) CMAPI Java… Rational Clearcase after 8.0.1.3 Fix from $2,3002018-04-20 HIGH 7.1 CVE-2014-0950 Multiple XML external entity (XXE) vulnerabilities in (1) CQWeb / CM Server, (2) ClearQuest Native client, (3) ClearQuest Eclipse client, and (4) Cle… Rational Clearquest after 8.0.1.3 Fix from $1,9502018-04-20 MEDIUM 6.5 CVE-2018-10175 Digital Guardian Management Console 7.1.2.0015 has an XXE issue. Management Console No fix yet Fix from $1,6002018-04-20 HIGH 7.5 CVE-2017-8315 Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit t… Ide No fix yet Fix from $1,9502018-04-20 HIGH 8.0 CVE-2017-6323 The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference… Management Console 8.1+ Fix from $1,9502018-04-16 HIGH 7.5 CVE-2018-1308EPSS 21% This vulnerability in Apache Solr 1.2 to 6.6.2 and 7.0.0 to 7.2.1 relates to an XML external entity expansion (XXE) in the `&dataConfig=<inlinexml>` … Solr after 7.2.1 Fix from $1,9502018-04-09 HIGH 7.1 CVE-2018-1421 IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing… Datapower Gateway after 7.6.0.5 Fix from $1,9502018-04-04 CRITICAL 9.1 CVE-2018-9116 An XXE vulnerability within WireMock before 2.16.0 allows a remote unauthenticated attacker to access local files and internal resources and potentia… Wiremock 2.16.0+ Fix from $2,3002018-03-29 MEDIUM 6.5 CVE-2015-7461 XML external entity (XXE) vulnerability in IBM Connections 3.0.1.1 and earlier, 4.0, 4.5, and 5.0 before CR4 allows remote authenticated users to cau… Connections after 3.0.1.1 Fix from $1,6002018-03-20 CRITICAL 9.8 CVE-2014-3990EPSS 7% The Cart::getProducts method in system/library/cart.php in OpenCart 1.5.6.4 and earlier allows remote attackers to conduct server-side request forger… Opencart after 1.5.6.4 Fix from $2,3002018-03-20 HIGH 8.8 CVE-2018-2401 SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML… Sap Business Process Automation Mitigation only Fix from $1,9502018-03-14 HIGH 7.5 CVE-2018-1077 Spacewalk 2.6 contains an API which has an XXE flaw allowing for the disclosure of potentially sensitive information from the server. Spacewalk Mitigation only Fix from $1,9502018-03-14 CRITICAL 10.0 CVE-2018-1000124 I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_s… I\, Librarian after 4.8 Fix from $2,3002018-03-13 HIGH 7.5 CVE-2018-1000090 textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the… Textpattern No fix yet Fix from $1,9502018-03-13 MEDIUM 5.5 CVE-2018-1000069 FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing da… Debian Linux after 1.5.9 Fix from $1,6002018-03-13 MEDIUM 5.4 CVE-2016-0250 XML external entity (XXE) vulnerability in IBM InfoSphere Information Governance Catalog 11.3 before 11.3.1.2 and 11.5 before 11.5.0.1 allows remote … Infosphere Information Server 11.3.1.2+ Fix from $1,6002018-03-12 MEDIUM 6.5 CVE-2018-5758 The Upload File functionality in upload.jspa in Aurea Jive Jive-n 9.0.2.1 On-Premises allows for an XML External Entity attack through a crafted file… Jive N No fix yet Fix from $1,6002018-03-12 HIGH 8.8 CVE-2018-7230 A XML external entity (XXE) vulnerability exists in the import.cgi of the web interface component of the Schneider Electric's Pelco Sarix Professiona… Mps110 1 Firmware 3.29.67+ Fix from $1,9502018-03-09 CRITICAL 9.1 CVE-2017-7426 The NetIQ Identity Manager Plugins before 4.6.1 contained various XML External XML Entity (XXE) handling flaws that could be used by attackers to lea… Identity Manager 4.6.1+ Fix from $2,3002018-03-01 CRITICAL 9.8 CVE-2017-18197 In mxGraphViewImageReader.java in mxGraph before 3.7.6, the SAXParserFactory instance in convert() is missing flags to prevent XML External Entity (X… Mxgraph after 3.7.5 Fix from $2,3002018-02-24 CRITICAL 9.8 CVE-2018-6489 XML External Entity (XXE) vulnerability in Micro Focus Project and Portfolio Management Center, version 9.32. This vulnerability can be exploited to … Project And Portfolio Management Center Mitigation only Fix from $2,3002018-02-22 HIGH 7.1 CVE-2017-1758 IBM Financial Transaction Manager for ACH Services for Multi-Platform (IBM Control Center 6.0 and 6.1, IBM Financial Transaction Manager 3.0.2, 3.0.3… Financial Transaction Manager Patch available Fix from $1,9502018-02-21 CRITICAL 9.8 CVE-2017-7375 A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida… Debian Linux after 2.9.4 Fix from $2,3002018-02-19 HIGH 8.1 CVE-2017-5828 An arbitrary command execution vulnerability in HPE Aruba ClearPass Policy Manager version 6.6.x was found. Aruba Clearpass Policy Manager 6.6.5+ Fix from $1,9502018-02-15 HIGH 7.5 CVE-2018-2392EPSS 41% Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus… Internet Graphics Server Mitigation only Fix from $1,9502018-02-14 HIGH 7.5 CVE-2018-2393EPSS 15% Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately caus… Internet Graphics Server Mitigation only Fix from $1,9502018-02-14