Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.5
CVE-2024-46985
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity injection vulnerability in the …
Dataease
2.10.1+
CRITICAL 9.8
CVE-2024-46984
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards. The profile lo…
Reference Validator
2.5.1+
CRITICAL 9.8
CVE-2024-7098
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.
This issue affects ww.Winsure…
Winsure
4.6.2+
HIGH 8.2
CVE-2024-37397EPSS 59%
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot…
Endpoint Manager
2022+
HIGH 8.8
CVE-2023-37233
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
Spectrum
4.6_hf14+
HIGH 8.6
CVE-2024-45294
The HL7 FHIR Core Artifacts repository provides the java core object handling code, with utilities (including validator), for the Fast Healthcare Int…
Mitigation only
HIGH 7.5
CVE-2024-45490
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
Libexpat
2.6.3+
MEDIUM 6.5
CVE-2024-45048
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows…
Phpspreadsheet
1.29.1 / 2.2.1+
HIGH 8.8
CVE-2024-22218
XML External Entity (XXE) vulnerability in Terminalfour 8.0.0001 through 8.3.18 and XML JDBC versions up to 1.0.4 allows authenticated users to submi…
Mitigation only
HIGH 7.5
CVE-2024-38653EPSS 92%
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-6893EPSS 33%
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This allows an unauthenticated attack…
Journyx
No fix yet
CRITICAL 9.8
CVE-2024-3930
In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.
Akana Api
2024.1.0+
HIGH 8.8
CVE-2023-48362
XXE in the XML Format Plugin in Apache Drill version 1.19.0 and greater allows a user to read any file on a remote file system or execute commands vi…
Drill
1.21.2+
MEDIUM 5.9
CVE-2024-6961
RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails users that consume RAIL docu…
Mitigation only
MEDIUM 6.5
CVE-2024-5625
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console allows Data Serialization Ex…
Mitigation only
HIGH 8.2
CVE-2023-50304
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML d…
Engineering Requirements Management Doors
Mitigation only
HIGH 7.5
CVE-2024-38374
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, validating, and parsing SBOMs. Befo…
Patch available
HIGH 7.5
CVE-2021-47621
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
Patch available
HIGH 7.2
CVE-2023-49110
When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web
application (either on-premises or cloud/SaaS solution), the transmit…
Mitigation only
CRITICAL 9.8
CVE-2024-34102 KEVEPSS 100%
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XX…
Commerce
1.5.0+
HIGH 7.5
CVE-2024-36827
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows attackers to access sensitive inf…
Ebookmeta
1.2.8+
CRITICAL 9.1
CVE-2024-37388
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of lxml before v4.9.1 allows attackers to access sensitive informat…
Ebookmeta
4.9.1+
HIGH 8.2
CVE-2023-45192
IBM Engineering Requirements Management DOORS Next 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML…
Doors Next
Mitigation only
CRITICAL 9.8
CVE-2024-3969
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execution by parsing untrusted XML…
Imanager
3.2.6+
MEDIUM 6.5
CVE-2024-4357
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege atta…
Telerik Reporting
10.1.24.514+
CRITICAL 9.8
CVE-2024-3486
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information disclosure and remote code executi…
Imanager
3.2.6+
HIGH 7.5
CVE-2024-30043EPSS 55%
Microsoft SharePoint Server Information Disclosure Vulnerability
Sharepoint Server
16.0.17328.20292+
HIGH 8.1
CVE-2024-34345
The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML External entity injections were pos…
Patch available
MEDIUM 6.5
CVE-2023-51605
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …
Saia Pg5 Controls Suite
Mitigation only
MEDIUM 6.5
CVE-2023-51600
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to …
Saia Pg5 Controls Suite
Mitigation only