Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.3 CVE-2018-1000056 Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user p… Junit after 1.23 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000054 Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user perm… Ccm after 3.1 Fix from $1,9502018-02-09 HIGH 8.3 CVE-2018-1000055 Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with … Android Lint after 2.5 Fix from $1,9502018-02-09 MEDIUM 6.5 CVE-2018-3600 A external entity processing information disclosure (XXE) vulnerability in Trend Micro Control Manager 6.0 could allow a remote attacker to disclose … Control Manager Patch available Fix from $1,6002018-02-09 HIGH 8.1 CVE-2018-1307 In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a local or remote XML document and then mediates the data… Juddi after 3.3.4 Fix from $1,9502018-02-09 HIGH 7.5 CVE-2018-5789 An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML … Wing 5.8.6.9 / 5.9.1.3+ Fix from $1,9502018-02-05 CRITICAL 9.8 CVE-2018-6486 XML External Entity (XXE) vulnerability in Micro Focus Fortify Audit Workbench (AWB) and Micro Focus Fortify Software Security Center (SSC), versions… Fortify Audit Workbench Mitigation only Fix from $2,3002018-02-02 CRITICAL 9.8 CVE-2014-3005EPSS 5% XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allow… Fedora Patch available Fix from $2,3002018-02-01 CRITICAL 9.8 CVE-2014-3244EPSS 5% XML external entity (XXE) vulnerability in the RSSDashlet dashlet in SugarCRM before 6.5.17 allows remote attackers to read arbitrary files or potent… Sugarcrm 6.5.16+ Fix from $2,3002018-02-01 MEDIUM 6.5 CVE-2017-14699 Multiple XML external entity (XXE) vulnerabilities in the AiCloud feature on ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U… Dsl Ac51 Firmware Patch available Fix from $1,6002018-01-29 HIGH 8.2 CVE-2018-1364 IBM Content Navigator 2.0 and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exp… Content Navigator Mitigation only Fix from $1,9502018-01-29 HIGH 8.8 CVE-2018-1000008 Jenkins PMD Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per… Pmd after 3.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000009 Jenkins Checkstyle Plugin 3.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with u… Checkstyle after 3.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000010 Jenkins DRY Plugin 2.49 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user per… Dry after 2.49 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000011 Jenkins FindBugs Plugin 4.71 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use… Findbugs after 4.71 Fix from $1,9502018-01-23 HIGH 8.8 CVE-2018-1000012 Jenkins Warnings Plugin 4.64 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with use… Warnings after 4.64 Fix from $1,9502018-01-23 MEDIUM 5.3 CVE-2018-0108 A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to collect customer files via an out-of-band XML Exter… Webex Meetings Server Mitigation only Fix from $1,6002018-01-18 MEDIUM 6.5 CVE-2016-0219 XML external entity (XXE) vulnerability in IBM Rational Team Concert 3.0 before 3.0.1.6 iFix7 Interim Fix 1, 4.0 before 4.0.7 iFix10, 5.0 before 5.0.… Rational Quality Manager Mitigation only Fix from $1,6002018-01-16 HIGH 8.1 CVE-2017-1666 IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote a… Security Key Lifecycle Manager Patch available Fix from $1,9502018-01-09 HIGH 7.5 CVE-2017-1000477 XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks. Xmlbundle No fix yet Fix from $1,9502018-01-03 HIGH 8.8 CVE-2017-1000496 Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execut… Commsy Mitigation only Fix from $1,9502018-01-03 CRITICAL 9.8 CVE-2017-1000497 Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code executi… Pepperminty Wiki Mitigation only Fix from $2,3002018-01-03 HIGH 7.8 CVE-2017-1000498 AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution Androidsvg Mitigation only Fix from $1,9502018-01-03 CRITICAL 9.8 CVE-2014-3630 XML external entity (XXE) vulnerability in the Java XML processing functionality in Play before 2.2.6 and 2.3.x before 2.3.5 might allow remote attac… Play Framework Mitigation only Fix from $2,3002017-12-29 CRITICAL 9.8 CVE-2017-14101 A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesso… Conserus Image Repository Mitigation only Fix from $2,3002017-12-15 HIGH 7.5 CVE-2017-11286EPSS 8% Adobe ColdFusion has an XML external entity (XXE) injection vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update… Coldfusion Patch available Fix from $1,9502017-12-01 HIGH 7.5 CVE-2017-14868 Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP… Restlet 2.3.11+ Fix from $1,9502017-11-30 HIGH 7.5 CVE-2017-14949 Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, be… Restlet 2.3.12+ Fix from $1,9502017-11-30 CRITICAL 9.1 CVE-2017-1000190 SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on. Solr after 2.7.1 Fix from $2,3002017-11-17 HIGH 8.1 CVE-2017-1477 IBM Security Access Manager Appliance 9.0.3 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker… Security Access Manager 9.0 Firmware Mitigation only Fix from $1,9502017-11-13