Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.8
CVE-2017-9096EPSS 10%
The XML parsers in iText before 5.5.12 and 7.x before 7.0.3 do not disable external entities, which might allow remote attackers to conduct XML exter…
Itext
5.5.12+
CRITICAL 9.8
CVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors inv…
Activemq Apollo
Mitigation only
CRITICAL 9.8
CVE-2014-3600EPSS 10%
XML external entity (XXE) vulnerability in Apache ActiveMQ 5.x before 5.10.1 allows remote consumers to have unspecified impact via vectors involving…
Activemq
Mitigation only
HIGH 7.8
CVE-2016-5002EPSS 8%
XML external entity (XXE) vulnerability in the Apache XML-RPC (aka ws-xmlrpc) library 3.1.3, as used in Apache Archiva, allows remote attackers to co…
Xml Rpc
Mitigation only
MEDIUM 6.5
CVE-2017-15639EPSS 7%
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.
Mura Cms
after 6.1
CRITICAL 9.8
CVE-2014-9487
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service…
Mediawiki
Mitigation only
CRITICAL 9.8
CVE-2017-12629EPSS 92%
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config API add-li…
Solr
after 7.0.1
MEDIUM 5.0
CVE-2017-10617
The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive sy…
Contrail
2.21.4 / 3.0.3.4+
MEDIUM 5.5
CVE-2017-15280
XML external entity (XXE) vulnerability in Umbraco CMS before 7.7.3 allows attackers to obtain sensitive information by reading files on the server o…
Umbraco Cms
after 7.7.2
MEDIUM 6.5
CVE-2017-12623
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The f…
Nifi
Mitigation only
CRITICAL 9.9
CVE-2017-13706
XML external entity (XXE) vulnerability in the import package functionality of the deployment module in Lansweeper before 6.0.100.67 allows remote au…
Lansweeper
after 6.0.100.29
CRITICAL 9.8
CVE-2014-0030EPSS 17%
The XML-RPC protocol support in Apache Roller before 5.0.3 allows attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.
Roller
No fix yet
CRITICAL 9.8
CVE-2017-14759
OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone …
Document Sciences Xpression
after 4.5
CRITICAL 9.8
CVE-2017-12620
When loading models or dictionaries that contain XML it is possible to perform an XXE attack, since Apache OpenNLP is a library, this only affects ap…
Opennlp
No fix yet
HIGH 7.8
CVE-2016-4434
Apache Tika before 1.13 does not properly initialize the XML parser or choose handlers, which might allow remote attackers to conduct XML External En…
Tika
Mitigation only
CRITICAL 9.8
CVE-2017-12621EPSS 9%
During Jelly (xml) file parsing with Apache Xerces, if a custom doctype entity is declared with a "SYSTEM" entity with a URL and that entity is used …
Commons Jelly
1.0.1+
HIGH 8.8
CVE-2017-14526
Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Administrator 7.2.0180.0055 allow remote authenticated users to list th…
Documentum Administrator
Mitigation only
HIGH 8.8
CVE-2017-14527
Multiple XML external entity (XXE) vulnerabilities in the OpenText Documentum Webtop 6.8.0160.0073 allow remote authenticated users to list the conte…
Documentum Administrator
No fix yet
HIGH 8.1
CVE-2017-1527
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attac…
Business Process Manager
Patch available
MEDIUM 5.5
CVE-2017-8918
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafte…
Dive Assistant
No fix yet
MEDIUM 6.5
CVE-2017-8040
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attac…
Single Sign On For Pivotal Cloud Foundry
Patch available
MEDIUM 5.5
CVE-2017-9095
XXE in Diving Log 6.0 allows attackers to remotely view local files through a crafted dive.xml file that is mishandled during a Subsurface import.
Diving Log
6.0.9+
HIGH 8.8
CVE-2017-12216
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to…
Socialminer
Mitigation only
CRITICAL 9.8
CVE-2017-9458
XML external entity (XXE) vulnerability in the GlobalProtect internal and external gateway interface in Palo Alto Networks PAN-OS before 6.1.18, 7.0.…
Pan Os
after 6.1.17
CRITICAL 9.8
CVE-2015-7241EPSS 13%
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
Netweaver
after 7.0
HIGH 8.1
CVE-2017-1458
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could explo…
Qradar Network Security
Mitigation only
HIGH 7.3
CVE-2016-5795
An XXE issue was discovered in Automated Logic Corporation (ALC) Liebert SiteScan Web Version 6.5 and prior, ALC WebCTRL Version 6.5 and prior, and C…
I Vu
after 6.5
HIGH 8.2
CVE-2017-12069
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Am…
Simatic Pcs7
after 2017-03-21
HIGH 7.5
CVE-2017-11272EPSS 13%
Adobe Digital Editions 4.5.4 and earlier has a security bypass vulnerability.
Digital Editions
after 4.5.5
HIGH 7.5
CVE-2016-8739EPSS 7%
The JAX-RS module in Apache CXF prior to 3.0.12 and 3.1.x prior to 3.1.9 provides a number of Atom JAX-RS MessageBodyReaders. These readers use Apach…
Cxf
after 3.0.11