Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.2
CVE-2017-1192
IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl…
Sterling B2b Integrator
Mitigation only
HIGH 7.4
CVE-2010-2245EPSS 12%
XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service…
Wink
after 1.1.1
HIGH 7.5
CVE-2017-11390
XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly Z…
Control Manager
Patch available
MEDIUM 6.5
CVE-2015-0194
XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers …
Sterling B2b Integrator
Patch available
CRITICAL 9.1
CVE-2017-1383
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot…
Infosphere Information Server
Mitigation only
HIGH 7.5
CVE-2017-9233EPSS 9%
XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop usi…
Python
2.7.15 / 3.3.7+
MEDIUM 6.5
CVE-2017-11457
XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o…
Netweaver Application Server Java
Mitigation only
MEDIUM 6.5
CVE-2017-1219
IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t…
Bigfix Platform
Mitigation only
CRITICAL 9.8
CVE-2016-6798
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string…
Sling
after 1.0.10
CRITICAL 10.0
CVE-2017-7664
Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0.
Openmeetings
Mitigation only
HIGH 7.1
CVE-2017-1000061
xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information discl…
Xmlsec
after 1.2.23
HIGH 8.8
CVE-2017-1000021
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.
Logicaldoc
after 7.5.3
MEDIUM 6.5
CVE-2017-0170EPSS 7%
Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windo…
Windows 10
Patch available
MEDIUM 5.5
CVE-2017-8557
Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1…
Windows 10
Patch available
HIGH 7.1
CVE-2017-1254
IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th…
Security Guardium
Mitigation only
CRITICAL 9.8
CVE-2017-10670
An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET),…
Osci Transport Library
Mitigation only
HIGH 8.2
CVE-2017-1322
IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this…
Api Connect
Patch available
HIGH 8.0
CVE-2017-6662
A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an aut…
Evolved Programmable Network Manager
Mitigation only
HIGH 7.5
CVE-2017-9231
XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via …
Xenmobile Server
Mitigation only
HIGH 8.1
CVE-2016-9698
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…
Rational Rhapsody Design Manager
Patch available
MEDIUM 6.5
CVE-2016-0254
IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proc…
Cognos Business Intelligence
Patch available
CRITICAL 9.8
CVE-2015-7326
XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3.
Webdav
after 2.7.0.1
MEDIUM 6.5
CVE-2017-2308
An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbit…
Junos Space
after 16.1
MEDIUM 6.5
CVE-2017-9295
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read…
Device Manager
after 8.5.2
CRITICAL 9.6
CVE-2016-6256EPSS 8%
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell…
Business One
No fix yet
HIGH 8.8
CVE-2014-0225
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d…
Spring Framework
Mitigation only
HIGH 8.8
CVE-2017-8913
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks…
Netweaver Application Server Java
Mitigation only
HIGH 8.2
CVE-2017-1289
IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit th…
Sdk
after 8
MEDIUM 6.6
CVE-2017-7907
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly rest…
Wonderware Historian Client
after 2014_r2
CRITICAL 9.8
CVE-2017-7503
It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th…
Jboss Enterprise Application Platform
Mitigation only