Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.3
CVE-2018-1000056
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p…
Junit
after 1.23
HIGH 8.3
CVE-2018-1000054
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm…
Ccm
after 3.1
HIGH 8.3
CVE-2018-1000055
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with …
Android Lint
after 2.5
MEDIUM 6.5
CVE-2018-3600
A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose …
Control Manager
Patch available
HIGH 8.1
CVE-2018-1307
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data…
Juddi
after 3.3.4
HIGH 7.5
CVE-2018-5789
An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML …
Wing
5.8.6.9 / 5.9.1.3+
CRITICAL 9.8
CVE-2018-6486
XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions…
Fortify Audit Workbench
Mitigation only
CRITICAL 9.8
CVE-2014-3005EPSS 5%
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allow…
Fedora
Patch available
CRITICAL 9.8
CVE-2014-3244EPSS 5%
XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent…
Sugarcrm
6.5.16+
MEDIUM 6.5
CVE-2017-14699
Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U…
Dsl Ac51 Firmware
Patch available
HIGH 8.2
CVE-2018-1364
IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp…
Content Navigator
Mitigation only
HIGH 8.8
CVE-2018-1000008
Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…
Pmd
after 3.49
HIGH 8.8
CVE-2018-1000009
Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with u…
Checkstyle
after 3.49
HIGH 8.8
CVE-2018-1000010
Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per…
Dry
after 2.49
HIGH 8.8
CVE-2018-1000011
Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…
Findbugs
after 4.71
HIGH 8.8
CVE-2018-1000012
Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use…
Warnings
after 4.64
MEDIUM 5.3
CVE-2018-0108
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML Exter…
Webex Meetings Server
Mitigation only
MEDIUM 6.5
CVE-2016-0219
XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.…
Rational Quality Manager
Mitigation only
HIGH 8.1
CVE-2017-1666
IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a…
Security Key Lifecycle Manager
Patch available
HIGH 7.5
CVE-2017-1000477
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
Xmlbundle
No fix yet
HIGH 8.8
CVE-2017-1000496
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execut…
Commsy
Mitigation only
CRITICAL 9.8
CVE-2017-1000497
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code executi…
Pepperminty Wiki
Mitigation only
HIGH 7.8
CVE-2017-1000498
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Androidsvg
Mitigation only
CRITICAL 9.8
CVE-2014-3630
XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attac…
Play Framework
Mitigation only
CRITICAL 9.8
CVE-2017-14101
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesso…
Conserus Image Repository
Mitigation only
HIGH 7.5
CVE-2017-11286EPSS 8%
Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update…
Coldfusion
Patch available
HIGH 7.5
CVE-2017-14868
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP…
Restlet
2.3.11+
HIGH 7.5
CVE-2017-14949
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, be…
Restlet
2.3.12+
CRITICAL 9.1
CVE-2017-1000190
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
Solr
after 2.7.1
HIGH 8.1
CVE-2017-1477
IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker…
Security Access Manager 9.0 Firmware
Mitigation only