Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2022-26661
An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tr…
Debian Linux
5.0.12 / 5.0.46+
MEDIUM 5.3
CVE-2022-21282
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JAXP). Supported versions that are affec…
Debian Linux
after 15.0.5
HIGH 7.5
CVE-2021-39371
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a pat…
Debian Linux
4.4.5+
HIGH 7.1
CVE-2019-17637
In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to …
Debian Linux
after 3.18
HIGH 8.1
CVE-2019-13031
LemonLDAP::NG before 1.9.20 has an XML External Entity (XXE) issue when submitting a notification to the notification server. By default, the notific…
Debian Linux
1.9.20+
MEDIUM 5.3
CVE-2019-9658
Checkstyle before 8.18 loads external DTDs by default.
Debian Linux
8.18+
CRITICAL 9.8
CVE-2018-14720EPSS 8%
FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspeci…
Debian Linux
2.6.7.2 / 2.7.9.5+
CRITICAL 9.8
CVE-2018-20433
c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.
Debian Linux
Patch available
MEDIUM 5.5
CVE-2018-1000069
FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing da…
Debian Linux
after 1.5.9
CRITICAL 9.8
CVE-2017-7375
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD valida…
Debian Linux
after 2.9.4
HIGH 7.5
CVE-2016-10149EPSS 5%
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request o…
Debian Linux
after 4.4.0
CRITICAL 9.1
CVE-2012-2239
Mahara 1.4.x before 1.4.4 and 1.5.x before 1.5.3 allows remote attackers to read arbitrary files or create TCP connections via an XML external entity…
Debian Linux
1.4.4 / 1.5.3+