Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 8.8 CVE-2024-52596 SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it'… Patch available Fix from $1,9502024-12-02 HIGH 8.3 CVE-2024-52806 SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse,… Patch available Fix from $1,9502024-12-02 HIGH 7.5 CVE-2024-53674EPSS 47% An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-53675EPSS 84% An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 HIGH 7.5 CVE-2024-11622 An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases. Insight Remote Support 7.14.0.629+ Fix from $1,9502024-11-26 CRITICAL 9.8 CVE-2023-24466 Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200. Imanager 3.2.6+ Fix from $2,3002024-11-22 MEDIUM 6.5 CVE-2024-50848 An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensit… Worldserver Mitigation only Fix from $1,6002024-11-18 HIGH 7.5 CVE-2024-48917 PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks.… Phpspreadsheet 1.29.4 / 2.1.3+ Fix from $1,9502024-11-18 HIGH 7.5 CVE-2024-47873 PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. H… Phpspreadsheet 1.29.4 / 2.1.3+ Fix from $1,9502024-11-18 MEDIUM 6.5 CVE-2020-26066 A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to in… Catalyst Sd Wan Manager Mitigation only Fix from $1,6002024-11-18 HIGH 8.2 CVE-2024-39726 IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when pro… Engineering Lifecycle Optimization Engineering Insights Mitigation only Fix from $1,9502024-11-15 MEDIUM 6.4 CVE-2021-1483 A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to in… Catalyst Sd Wan Manager Mitigation only Fix from $1,6002024-11-15 CRITICAL 9.8 CVE-2021-3902 An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and dese… Dompdf 2.0.0+ Fix from $2,3002024-11-15 MEDIUM 6.5 CVE-2024-5919 A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate… Pan Os 10.1.10 / 10.2.5+ Fix from $1,6002024-11-14 CRITICAL 9.2 CVE-2024-10218 XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational I… No fix yet Fix from $2,3002024-11-12 HIGH 8.6 CVE-2024-52007 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components… Patch available Fix from $1,9502024-11-08 HIGH 8.1 CVE-2024-10839 Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management opt… Manageengine Sharepoint Manager Plus Mitigation only Fix from $1,9502024-11-08 MEDIUM 6.5 CVE-2024-20531 A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of a… Identity Services Engine Mitigation only Fix from $1,6002024-11-06 CRITICAL 9.8 CVE-2024-51132 An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via … Mitigation only Fix from $2,3002024-11-05 MEDIUM 5.5 CVE-2024-45086 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged us… Websphere Application Server 8.5.5.27 / 9.0.5.22+ Fix from $1,6002024-11-04 CRITICAL 9.8 CVE-2024-51136 An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code… Openimaj No fix yet Fix from $2,3002024-11-04 HIGH 7.2 CVE-2024-50442 Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-addons allows XML Injection.Th… Royal Elementor Addons 1.3.981+ Fix from $1,9502024-10-28 HIGH 8.0 CVE-2024-4184 Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects … Application Automation Tools after 24.1.0 Fix from $1,9502024-10-16 HIGH 8.0 CVE-2024-4189 Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects … Application Automation Tools after 24.1.0 Fix from $1,9502024-10-16 HIGH 8.0 CVE-2024-4690 Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects … Application Automation Tools after 24.1.0 Fix from $1,9502024-10-16 MEDIUM 5.5 CVE-2024-45072 IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A privileged us… Websphere Application Server after 9.0.5.21 Fix from $1,6002024-10-16 HIGH 8.8 CVE-2024-21255 Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: XMLPublisher). Supported versions that are affected … Peoplesoft Enterprise Peopletools Mitigation only Fix from $1,9502024-10-15 MEDIUM 6.3 CVE-2024-8602 When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentBuilder allow for an XXE (XML … Mitigation only Fix from $1,6002024-10-14 HIGH 7.5 CVE-2024-28168 Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: … Formatting Objects Processor Mitigation only Fix from $1,9502024-10-09 HIGH 7.5 CVE-2024-45293 PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for preventing XXE attacks in the XL… Phpspreadsheet 1.29.1 / 2.1.1+ Fix from $1,9502024-10-07