Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.1 CVE-2017-1103 IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remot… Rational Team Concert Patch available Fix from $1,9502017-05-10 HIGH 8.6 CVE-2016-9691 IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when … Websphere Cast Iron Solution Patch available Fix from $1,9502017-05-05 HIGH 8.1 CVE-2017-1149 IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proces… Urbancode Deploy Mitigation only Fix from $1,9502017-04-25 CRITICAL 10.0 CVE-2017-8110 www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php. Modified Ecommerce Shopsoftware Mitigation only Fix from $2,3002017-04-25 MEDIUM 6.5 CVE-2017-3548EPSS 51% Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions… Peoplesoft Enterprise Peopletools Patch available Fix from $1,6002017-04-24 MEDIUM 5.3 CVE-2017-8056EPSS 5% WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox… Fireware after 11.2.1 Fix from $1,6002017-04-22 HIGH 7.3 CVE-2017-5661 In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S… Formatting Objects Processor after 2.1 Fix from $1,9502017-04-18 HIGH 7.3 CVE-2017-5662 In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously form… Batik after 1.8 Fix from $1,9502017-04-18 HIGH 8.6 CVE-2016-7051 XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct… Jackson Dataformat Xml 2.7.8+ Fix from $1,9502017-04-14 MEDIUM 5.0 CVE-2017-7457 XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure. Mx Aopc Server No fix yet Fix from $1,6002017-04-14 CRITICAL 9.8 CVE-2015-7273 Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE. Integrated Remote Access Controller Firmware after 2.20.20.20 Fix from $2,3002017-04-10 MEDIUM 5.9 CVE-2016-6805 Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents. Ignite after 1.8 Fix from $1,6002017-04-07 CRITICAL 9.1 CVE-2016-6111 IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when pr… Curam Social Program Management Patch available Fix from $2,3002017-03-31 HIGH 8.1 CVE-2016-9707 IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote a… Rational Rhapsody Design Manager Patch available Fix from $1,9502017-03-31 CRITICAL 9.8 CVE-2016-9924 Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks. Zimbra Collaboration Suite after 8.7.3 Fix from $2,3002017-03-29 HIGH 7.5 CVE-2016-10149EPSS 5% XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request o… Debian Linux after 4.4.0 Fix from $1,9502017-03-24 CRITICAL 9.8 CVE-2017-6895 USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml. Usb Pratirodh No fix yet Fix from $2,3002017-03-23 MEDIUM 5.5 CVE-2016-5748 External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 5.5 CVE-2016-5749 NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which cou… Access Manager Mitigation only Fix from $1,6002017-03-23 MEDIUM 6.5 CVE-2016-4931 XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service. Junos Space after 15.2 Fix from $1,6002017-03-20 MEDIUM 6.5 CVE-2017-3811 An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the … Webex Meetings Server Mitigation only Fix from $1,6002017-03-17 HIGH 8.1 CVE-2016-9724 IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attack… Qradar Security Information And Event Manager Patch available Fix from $1,9502017-03-07 CRITICAL 9.0 CVE-2016-10127 PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response. Pysaml2 Patch available Fix from $2,3002017-03-03 MEDIUM 5.9 CVE-2017-6344 XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document. Pdf Plugin No fix yet Fix from $1,6002017-02-27 HIGH 8.1 CVE-2016-8974 IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML dat… Rational Rhapsody Design Manager Patch available Fix from $1,9502017-02-23 HIGH 7.8 CVE-2017-6055 XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrar… Eparakstitajs 3 after 1.3.8 Fix from $1,9502017-02-17 HIGH 7.5 CVE-2016-4312EPSS 6% XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote aut… Identity Server Patch available Fix from $1,9502017-02-17 CRITICAL 9.1 CVE-2016-9706 IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injec… Integration Bus Patch available Fix from $2,3002017-02-15 HIGH 8.2 CVE-2017-5992 Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document. Openpyxl Patch available Fix from $1,9502017-02-15 CRITICAL 9.8 CVE-2016-8348 An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Li… Liebert Sitescan Web after 6.5 Fix from $2,3002017-02-13