Vulnerability index

Browse CVEs

1,205 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
HIGH 7.5 CVE-2024-46985 DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the … Dataease 2.10.1+ Fix from $1,9502024-09-23 CRITICAL 9.8 CVE-2024-46984 The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile lo… Reference Validator 2.5.1+ Fix from $2,3002024-09-19 CRITICAL 9.8 CVE-2024-7098 Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection. This issue affects ww.Winsure… Winsure 4.6.2+ Fix from $2,3002024-09-16 HIGH 8.2 CVE-2024-37397EPSS 59% An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2023-37233 Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks. Spectrum 4.6_hf14+ Fix from $1,9502024-09-10 HIGH 8.6 CVE-2024-45294 The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Int… Mitigation only Fix from $1,9502024-09-06 HIGH 7.5 CVE-2024-45490 An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer. Libexpat 2.6.3+ Fix from $1,9502024-08-30 MEDIUM 6.5 CVE-2024-45048 PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows… Phpspreadsheet 1.29.1 / 2.2.1+ Fix from $1,6002024-08-28 HIGH 8.8 CVE-2024-22218 XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submi… Mitigation only Fix from $1,9502024-08-15 HIGH 7.5 CVE-2024-38653EPSS 92% XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-6893EPSS 33% The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attack… Journyx No fix yet Fix from $1,9502024-08-08 CRITICAL 9.8 CVE-2024-3930 In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered. Akana Api 2024.1.0+ Fix from $2,3002024-07-30 HIGH 8.8 CVE-2023-48362 XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi… Drill 1.21.2+ Fix from $1,9502024-07-24 MEDIUM 5.9 CVE-2024-6961 RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL docu… Mitigation only Fix from $1,6002024-07-21 MEDIUM 6.5 CVE-2024-5625 Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization Ex… Mitigation only Fix from $1,6002024-07-18 HIGH 8.2 CVE-2023-50304 IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d… Engineering Requirements Management Doors Mitigation only Fix from $1,9502024-07-18 HIGH 7.5 CVE-2024-38374 The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Befo… Patch available Fix from $1,9502024-06-28 HIGH 7.5 CVE-2021-47621 ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks. Patch available Fix from $1,9502024-06-21 HIGH 7.2 CVE-2023-49110 When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud/SaaS solution), the transmit… Mitigation only Fix from $1,9502024-06-20 CRITICAL 9.8 CVE-2024-34102 KEVEPSS 100% Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX… Commerce 1.5.0+ Fix from $2,3002024-06-13 HIGH 7.5 CVE-2024-36827 An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive inf… Ebookmeta 1.2.8+ Fix from $1,9502024-06-07 CRITICAL 9.1 CVE-2024-37388 An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive informat… Ebookmeta 4.9.1+ Fix from $2,3002024-06-07 HIGH 8.2 CVE-2023-45192 IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML… Doors Next Mitigation only Fix from $1,9502024-06-06 CRITICAL 9.8 CVE-2024-3969 XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML… Imanager 3.2.6+ Fix from $2,3002024-05-28 MEDIUM 6.5 CVE-2024-4357 An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege atta… Telerik Reporting 10.1.24.514+ Fix from $1,6002024-05-15 CRITICAL 9.8 CVE-2024-3486 XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code executi… Imanager 3.2.6+ Fix from $2,3002024-05-15 HIGH 7.5 CVE-2024-30043EPSS 55% Microsoft SharePoint Server Information Disclosure Vulnerability Sharepoint Server 16.0.17328.20292+ Fix from $1,9502024-05-14 HIGH 8.1 CVE-2024-34345 The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were pos… Patch available Fix from $1,9502024-05-14 MEDIUM 6.5 CVE-2023-51605 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03 MEDIUM 6.5 CVE-2023-51600 Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to … Saia Pg5 Controls Suite Mitigation only Fix from $1,6002024-05-03