V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
Filters

All vulnerabilities

104 / 104
Preset: exploit×Has exploit×CWE: CWE-611×Clear all
9.8
CVE-2019-9670CVE KEV
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML Exte…
2019-01-01KEV
EPSS94.4%
pct 99
8.3
CVE-2024-22024CVE
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x…
2024-01-01Pre-auth
EPSS94.2%
pct 99
9.8
CVE-2022-28219CVE
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE at…
2022-01-01Pre-auth
EPSS94.2%
pct 99
9.8
CVE-2024-34102ANC KEV
Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Impr…
2024-01-01KEV
EPSS94.2%
pct 99
9.8
CVE-2017-12629DEB
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploit…
2017-01-01Pre-auth
EPSS93.9%
pct 99
6.5
CVE-2021-29447DEB
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can e…
2021-01-01
EPSS90.8%
pct 99
7.5
CVE-2022-2414DEB
Access to external entities when parsing XML documents can lead to XML external entity (XXE) at…
2022-01-01Pre-auth
EPSS90.7%
pct 99
8.2
CVE-2020-4463CVE
IBM Maximo Asset Management 7.6.0.1 and 7.6.0.2 is vulnerable to an XML External Entity Injecti…
2020-01-01Pre-auth
EPSS85.8%
pct 99
9.8
CVE-2025-58360ANC KEV
GeoServer is an open source server that allows users to share and edit geospatial data. From ve…
2025-01-01KEV
EPSS81.4%
pct 99
7.5
CVE-2019-13608CVE KEV
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8…
2019-01-01KEV
EPSS71.7%
pct 98
7.5
CVE-2025-2775CVE KEV
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XX…
2025-01-01KEV
EPSS69.3%
pct 98
9.8
CVE-2025-2776CVE KEV
SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XX…
2025-01-01KEV
EPSS62.6%
pct 98
7.5
CVE-2022-38840CVE
cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE…
2022-01-01Pre-auth
EPSS60.1%
pct 98
7.5
CVE-2024-30043ANC
Microsoft SharePoint Server Information Disclosure Vulnerability
2024-01-01MicrosoftPre-auth
EPSS59.3%
pct 98
6.5
CVE-2016-9563CVE KEV
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML Ex…
2016-01-01KEV
EPSS58.8%
pct 98
9.8
CVE-2018-13416CVE
In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vu…
2018-01-01Pre-auth
EPSS55.8%
pct 98
8.6
CVE-2016-4264CVE
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Updat…
2016-01-01Pre-auth
EPSS55.4%
pct 98
9.1
CVE-2012-3363DEB
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly han…
2012-01-01Pre-auth
EPSS55.1%
pct 98
8.8
CVE-2018-8420MSR
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser …
2018-01-01MicrosoftPre-auth
EPSS53.1%
pct 98
5.5
CVE-2019-17554CVE
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not config…
2019-01-01
EPSS52.5%
pct 97
6.5
CVE-2017-3548CVE
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products …
2017-01-01Pre-auth
EPSS49.2%
pct 97
5.5
CVE-2018-8533CVE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS)…
2018-01-01
EPSS47.9%
pct 97
5.5
CVE-2018-8532CVE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS)…
2018-01-01
EPSS47.9%
pct 97
5.5
CVE-2018-8527CVE
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS)…
2018-01-01
EPSS47.9%
pct 97
9.8
CVE-2018-13417DEB
In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulner…
2018-01-01Pre-auth
EPSS47.4%
pct 97
4.7
CVE-2019-0948MSR
An information disclosure vulnerability exists in the Windows Event Viewer (eventvwr.msc) when …
2019-01-01Microsoft
EPSS41.4%
pct 97
9.8
CVE-2018-14485CVE
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
2018-01-01Pre-auth
EPSS40.5%
pct 97
3.1
CVE-2018-0878MSR
Windows Remote Assistance in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windo…
2018-01-01MicrosoftPre-auth
EPSS40.4%
pct 97
7.5
CVE-2019-13358CVE
lib/DocumentToText.php in OpenCats before 0.9.4-3 has XXE that allows remote users to read file…
2019-01-01Pre-auth
EPSS39.7%
pct 97
7.1
CVE-2018-1247CVE
RSA Authentication Manager Security Console, version 8.3 and earlier, contains a XML External E…
2018-01-01
EPSS35.3%
pct 97
9.8
CVE-2018-11586CVE
XML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote un…
2018-01-01Pre-auth
EPSS32.6%
pct 96
9.8
CVE-2018-13415CVE
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnera…
2018-01-01Pre-auth
EPSS32.1%
pct 96
4.0
CVE-2015-2125CVE
Unspecified vulnerability in HP WebInspect 7.x through 10.4 before 10.4 update 1 allows remote …
2015-01-01
EPSS31.0%
pct 96
9.8
CVE-2015-7241CVE
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
2015-01-01Pre-auth
EPSS27.4%
pct 96
7.3
CVE-2018-11788DEB
Apache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by…
2018-01-01Pre-auth
EPSS24.7%
pct 96
9.1
CVE-2018-1821CVE
IBM Operational Decision Management 8.5, 8.6, 8.7, 8.8, and 8.9 is vulnerable to a XML External…
2018-01-01Pre-auth
EPSS23.8%
pct 96
7.5
CVE-2012-4399DEB
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to r…
2012-01-01Pre-auth
EPSS22.7%
pct 95
8.1
CVE-2019-15637CVE
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data so…
2019-01-01
EPSS22.4%
pct 95
9.8
CVE-2018-12463CVE
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 1…
2018-01-01Pre-auth
EPSS21.9%
pct 95
7.5
CVE-2023-45727CVE KEV
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and ea…
2023-01-01KEV
EPSS21.0%
pct 95
Select a vulnerability on the left to open the preview.