Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.8 CVE-2017-9096EPSS 10% The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML exter… Itext 5.5.12+ Fix from $1,9502017-11-08 CRITICAL 9.8 CVE-2014-3579 XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv… Activemq Apollo Mitigation only Fix from $2,3002017-10-27 CRITICAL 9.8 CVE-2014-3600EPSS 10% XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving… Activemq Mitigation only Fix from $2,3002017-10-27 HIGH 7.8 CVE-2016-5002EPSS 8% XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co… Xml Rpc Mitigation only Fix from $1,9502017-10-27 MEDIUM 6.5 CVE-2017-15639EPSS 7% tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature. Mura Cms after 6.1 Fix from $1,6002017-10-19 CRITICAL 9.8 CVE-2014-9487 The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service… Mediawiki Mitigation only Fix from $2,3002017-10-17 CRITICAL 9.8 CVE-2017-12629EPSS 92% Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li… Solr after 7.0.1 Fix from $2,3002017-10-14 MEDIUM 5.0 CVE-2017-10617 The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sy… Contrail 2.21.4 / 3.0.3.4+ Fix from $1,6002017-10-13 MEDIUM 5.5 CVE-2017-15280 XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server o… Umbraco Cms after 7.7.2 Fix from $1,6002017-10-12 MEDIUM 6.5 CVE-2017-12623 An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f… Nifi Mitigation only Fix from $1,6002017-10-10 CRITICAL 9.9 CVE-2017-13706 XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote au… Lansweeper after 6.0.100.29 Fix from $2,3002017-10-10 CRITICAL 9.8 CVE-2014-0030EPSS 17% The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors. Roller No fix yet Fix from $2,3002017-10-10 CRITICAL 9.8 CVE-2017-14759 OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone … Document Sciences Xpression after 4.5 Fix from $2,3002017-10-03 CRITICAL 9.8 CVE-2017-12620 When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap… Opennlp No fix yet Fix from $2,3002017-10-03 HIGH 7.8 CVE-2016-4434 Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En… Tika Mitigation only Fix from $1,9502017-09-30 CRITICAL 9.8 CVE-2017-12621EPSS 9% During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used … Commons Jelly 1.0.1+ Fix from $2,3002017-09-28 HIGH 8.8 CVE-2017-14526 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list th… Documentum Administrator Mitigation only Fix from $1,9502017-09-28 HIGH 8.8 CVE-2017-14527 Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the conte… Documentum Administrator No fix yet Fix from $1,9502017-09-28 HIGH 8.1 CVE-2017-1527 IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attac… Business Process Manager Patch available Fix from $1,9502017-09-26 MEDIUM 5.5 CVE-2017-8918 XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafte… Dive Assistant No fix yet Fix from $1,6002017-09-12 MEDIUM 6.5 CVE-2017-8040 In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attac… Single Sign On For Pivotal Cloud Foundry Patch available Fix from $1,6002017-09-09 MEDIUM 5.5 CVE-2017-9095 XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import. Diving Log 6.0.9+ Fix from $1,6002017-09-08 HIGH 8.8 CVE-2017-12216 A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to… Socialminer Mitigation only Fix from $1,9502017-09-07 CRITICAL 9.8 CVE-2017-9458 XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.… Pan Os after 6.1.17 Fix from $2,3002017-09-07 CRITICAL 9.8 CVE-2015-7241EPSS 13% XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01. Netweaver after 7.0 Fix from $2,3002017-09-06 HIGH 8.1 CVE-2017-1458 IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo… Qradar Network Security Mitigation only Fix from $1,9502017-09-05 HIGH 7.3 CVE-2016-5795 An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and C… I Vu after 6.5 Fix from $1,9502017-08-31 HIGH 8.2 CVE-2017-12069 An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Am… Simatic Pcs7 after 2017-03-21 Fix from $1,9502017-08-30 HIGH 7.5 CVE-2017-11272EPSS 13% Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability. Digital Editions after 4.5.5 Fix from $1,9502017-08-11 HIGH 7.5 CVE-2016-8739EPSS 7% The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apach… Cxf after 3.0.11 Fix from $1,9502017-08-10