Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Debian Linux MEDIUM 6.5
CVE-2022-26661

An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tr…

Fix: 5.0.12 / 5.0.46+
Fix from $1,600 2022-03-10
Debian Linux MEDIUM 5.3
CVE-2022-21282

Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…

Fix: after 15.0.5
Fix from $1,600 2022-01-19
Debian Linux HIGH 7.5
CVE-2021-39371

An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a pat…

Fix: 4.4.5+
Fix from $1,950 2021-08-23
Debian Linux HIGH 7.1
CVE-2019-17637

In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to …

Fix: after 3.18
Fix from $1,950 2020-07-15
Debian Linux HIGH 8.1
CVE-2019-13031

LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific…

Fix: 1.9.20+
Fix from $1,950 2019-06-28
Debian Linux MEDIUM 5.3
CVE-2019-9658

Checkstyle before 8.18 loads external DTDs by default.

Fix: 8.18+
Fix from $1,600 2019-03-11
Debian Linux CRITICAL 9.8
CVE-2018-14720EPSS 8%

FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…

Fix: 2.6.7.2 / 2.7.9.5+
Fix from $2,300 2019-01-02
Debian Linux CRITICAL 9.8
CVE-2018-20433

c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

Patch available
Fix from $2,300 2018-12-24
Debian Linux MEDIUM 5.5
CVE-2018-1000069

FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing da…

Fix: after 1.5.9
Fix from $1,600 2018-03-13
Debian Linux CRITICAL 9.8
CVE-2017-7375

A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…

Fix: after 2.9.4
Fix from $2,300 2018-02-19
Debian Linux HIGH 7.5
CVE-2016-10149EPSS 5%

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request o…

Fix: after 4.4.0
Fix from $1,950 2017-03-24
Debian Linux CRITICAL 9.1
CVE-2012-2239

Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity…

Fix: 1.4.4 / 1.5.3+
Fix from $2,300 2012-11-24