Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 8.1
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remo…
License Metric Tool
Mitigation only
HIGH 8.1
CVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML da…
Infosphere Datastage
Patch available
CRITICAL 9.1
CVE-2016-2908
IBM Single Sign On for Bluemix could allow a remote attacker to obtain sensitive information, caused by a XML external entity (XXE) error when proces…
Security Access Manager 9.0 Firmware
Patch available
MEDIUM 6.5
CVE-2016-3027
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML …
Security Access Manager 9.0 Firmware
Patch available
MEDIUM 6.5
CVE-2015-7743
XML external entity vulnerability in PRTG Network Monitor before 16.2.23.3077/3078 allows remote authenticated users to read arbitrary files by creat…
Prtg Network Monitor
after 14.4.12.3282
HIGH 7.5
CVE-2016-10097
XML External Entity (XXE) Vulnerability in /SSOPOST/metaAlias/%realm%/idpv2 in OpenAM - Access Management 10.1.0 allows remote attackers to read arbi…
Openam
Mitigation only
MEDIUM 5.8
CVE-2016-7458
VMware vSphere Client 5.5 before U3e and 6.0 before U2a allows remote vCenter Server and ESXi instances to read arbitrary files via an XML document c…
Vsphere Client
Mitigation only
HIGH 7.7
CVE-2016-7459
VMware vCenter Server 5.5 before U3e and 6.0 before U2a allows remote authenticated users to read arbitrary files via a (1) Log Browser, (2) Distribu…
Vcenter Server
Patch available
CRITICAL 9.1
CVE-2016-7460
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attacker…
Vrealize Automation
Mitigation only
CRITICAL 9.1
CVE-2016-9180
perl-XML-Twig: The option to `expand_external_ents`, documented as controlling external entity expansion in XML::Twig does not work. External entitie…
Xml Twig For Perl
Mitigation only
HIGH 7.1
CVE-2016-9181
perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processe…
Image Info For Perl
Mitigation only
HIGH 8.8
CVE-2016-5851
python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.
Python Docx
after 0.8.5
HIGH 8.1
CVE-2016-3055
IBM FileNet Workplace 4.0.2 before 4.0.2.14 LA012 allows remote authenticated users to read arbitrary files or cause a denial of service (memory cons…
Filenet Workplace
Patch available
HIGH 8.1
CVE-2016-3033
IBM AppScan Source 8.7 through 9.0.3.3 allows remote authenticated users to read arbitrary files or cause a denial of service (memory consumption) vi…
Appscan Source
Mitigation only
MEDIUM 5.4
CVE-2016-0284
The XML parser in IBM Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.0 before 4.0.7 iFix11, 5.0 before 5.0.2 iFix18, and 6.0 bef…
Rational Software Architect Design Manager
Mitigation only
MEDIUM 6.5
CVE-2016-9563 KEVEPSS 24%
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tc~bpem~hi…
Netweaver Application Server Java
Mitigation only
MEDIUM 5.5
CVE-2016-9318
libxml2 2.9.4 and earlier, as used in XMLSec 1.2.23 and earlier and other products, does not offer a flag directly indicating that the current docume…
Ubuntu Linux
after 2.9.4
CRITICAL 9.1
CVE-2015-1832EPSS 12%
XML external entity (XXE) vulnerability in the SqlXmlUtil code in Apache Derby before 10.12.1.1, when a Java Security Manager is not in place, allows…
Derby
Mitigation only
HIGH 7.1
CVE-2016-5971
IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8 allows remote authenticated users to read arbitrary files or …
Security Privileged Identity Manager Virtual Appliance
after 2.0.2
HIGH 7.5
CVE-2016-6408
Cisco Prime Home 5.2.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction w…
Prime Home
Mitigation only
HIGH 8.6
CVE-2016-4264EPSS 69%
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files o…
Coldfusion
after 11.0
MEDIUM 5.5
CVE-2016-5000
The XLSX2CSV example in Apache POI before 3.14 allows remote attackers to read arbitrary files via a crafted OpenXML document containing an external …
Poi
after 3.13
CRITICAL 9.6
CVE-2015-8866
ext/libxml/libxml.c in PHP before 5.5.22 and 5.6.x before 5.6.6, when PHP-FPM is used, does not isolate each thread from libxml_disable_entity_loader…
PHP
5.5.22 / 5.6.6+
CRITICAL 9.1
CVE-2016-3974EPSS 15%
XML external entity (XXE) vulnerability in the Configuration Wizard in SAP NetWeaver Java AS 7.1 through 7.5 allows remote attackers to cause a denia…
Netweaver Application Server Java
after 7.50
MEDIUM 5.0
CVE-2015-3451
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML exter…
Xml Libxml
after 2.0118
MEDIUM 6.8
CVE-2013-6429EPSS 90%
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolut…
Spring Framework
after 3.2.4
MEDIUM 6.8
CVE-2013-0340EPSS 19%
expat before version 2.4.0 does not properly handle entities expansion unless an application developer uses the XML_SetEntityDeclHandler function, wh…
Python
2.4.0 / 3.6.15+
HIGH 7.5
CVE-2013-1915
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU a…
Fedora
2.7.3+
CRITICAL 9.1
CVE-2012-3363EPSS 50%
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote atta…
Fedora
1.11.12+
MEDIUM 5.5
CVE-2012-5656
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML exter…
Fedora
0.48.4+