Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.2 CVE-2017-1192 IBM Sterling B2B Integrator 5.2 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could expl… Sterling B2b Integrator Mitigation only Fix from $1,9502017-08-10 HIGH 7.4 CVE-2010-2245EPSS 12% XML External Entity (XXE) vulnerability in Apache Wink 1.1.1 and earlier allows remote attackers to read arbitrary files or cause a denial of service… Wink after 1.1.1 Fix from $1,9502017-08-08 HIGH 7.5 CVE-2017-11390 XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly Z… Control Manager Patch available Fix from $1,9502017-08-02 MEDIUM 6.5 CVE-2015-0194 XML External Entity (XXE) vulnerability in IBM Sterling B2B Integrator 5.1 and 5.2 and IBM Sterling File Gateway 2.1 and 2.2 allows remote attackers … Sterling B2b Integrator Patch available Fix from $1,6002017-08-02 CRITICAL 9.1 CVE-2017-1383 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remot… Infosphere Information Server Mitigation only Fix from $2,3002017-08-02 HIGH 7.5 CVE-2017-9233EPSS 9% XML External Entity vulnerability in libexpat 2.2.0 and earlier (Expat XML Parser Library) allows attackers to put the parser in an infinite loop usi… Python 2.7.15 / 3.3.7+ Fix from $1,9502017-07-25 MEDIUM 6.5 CVE-2017-11457 XML external entity (XXE) vulnerability in com.sap.km.cm.ice in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to read arbitrary files o… Netweaver Application Server Java Mitigation only Fix from $1,6002017-07-25 MEDIUM 6.5 CVE-2017-1219 IBM Tivoli Endpoint Manager is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit t… Bigfix Platform Mitigation only Fix from $1,6002017-07-19 CRITICAL 9.8 CVE-2016-6798 In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string… Sling after 1.0.10 Fix from $2,3002017-07-19 CRITICAL 10.0 CVE-2017-7664 Uploaded XML documents were not correctly validated in Apache OpenMeetings 3.1.0. Openmeetings Mitigation only Fix from $2,3002017-07-17 HIGH 7.1 CVE-2017-1000061 xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information discl… Xmlsec after 1.2.23 Fix from $1,9502017-07-17 HIGH 8.8 CVE-2017-1000021 LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents. Logicaldoc after 7.5.3 Fix from $1,9502017-07-17 MEDIUM 6.5 CVE-2017-0170EPSS 7% Windows Performance Monitor in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windo… Windows 10 Patch available Fix from $1,6002017-07-11 MEDIUM 5.5 CVE-2017-8557 Windows System Information Console in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1… Windows 10 Patch available Fix from $1,6002017-07-11 HIGH 7.1 CVE-2017-1254 IBM Security Guardium 10.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit th… Security Guardium Mitigation only Fix from $1,9502017-07-05 CRITICAL 9.8 CVE-2017-10670 An XML External Entity (XXE) issue exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET),… Osci Transport Library Mitigation only Fix from $2,3002017-06-30 HIGH 8.2 CVE-2017-1322 IBM API Connect 5.0.6.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this… Api Connect Patch available Fix from $1,9502017-06-27 HIGH 8.0 CVE-2017-6662 A vulnerability in the web-based user interface of Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) could allow an aut… Evolved Programmable Network Manager Mitigation only Fix from $1,9502017-06-26 HIGH 7.5 CVE-2017-9231 XML external entity (XXE) vulnerability in Citrix XenMobile Server 9.x and 10.x before 10.5 RP3 allows attackers to obtain sensitive information via … Xenmobile Server Mitigation only Fix from $1,9502017-06-16 HIGH 8.1 CVE-2016-9698 IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da… Rational Rhapsody Design Manager Patch available Fix from $1,9502017-06-08 MEDIUM 6.5 CVE-2016-0254 IBM Cognos Business Intelligence 10.1 and 10.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proc… Cognos Business Intelligence Patch available Fix from $1,6002017-06-07 CRITICAL 9.8 CVE-2015-7326 XML External Entity (XXE) vulnerability in Milton Webdav before 2.7.0.3. Webdav after 2.7.0.1 Fix from $2,3002017-06-07 MEDIUM 6.5 CVE-2017-2308 An XML External Entity Injection vulnerability in Juniper Networks Junos Space versions prior to 16.1R1 may allow an authenticated user to read arbit… Junos Space after 16.1 Fix from $1,6002017-05-30 MEDIUM 6.5 CVE-2017-9295 XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read… Device Manager after 8.5.2 Fix from $1,6002017-05-29 CRITICAL 9.6 CVE-2016-6256EPSS 8% SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML data in a request to B1iXcell… Business One No fix yet Fix from $2,3002017-05-26 HIGH 8.8 CVE-2014-0225 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not d… Spring Framework Mitigation only Fix from $1,9502017-05-25 HIGH 8.8 CVE-2017-8913 The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks… Netweaver Application Server Java Mitigation only Fix from $1,9502017-05-23 HIGH 8.2 CVE-2017-1289 IBM SDK, Java Technology Edition is vulnerable XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit th… Sdk after 8 Fix from $1,9502017-05-22 MEDIUM 6.6 CVE-2017-7907 An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly rest… Wonderware Historian Client after 2014_r2 Fix from $1,6002017-05-19 CRITICAL 9.8 CVE-2017-7503 It was found that the Red Hat JBoss EAP 7.0.5 implementation of javax.xml.transform.TransformerFactory is vulnerable to XXE. An attacker could use th… Jboss Enterprise Application Platform Mitigation only Fix from $2,3002017-05-18