All vulnerabilities
80 / 80
Sort
7.5
CVE-2009-1955DEB
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.…
2009-01-01Pre-auth
EPSS53.3%
pct 98
7.6
CVE-2017-18640DEB
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a r…
2017-01-01Pre-auth
EPSS26.7%
pct 97
7.5
CVE-2018-11761DEB
In Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They…
2018-01-01Pre-auth
EPSS9.6%
pct 94
7.5
CVE-2019-12401DEB
Solr versions 1.3.0 to 1.4.1, 3.1.0 to 3.6.2 and 4.0.0 to 4.10.4 are vulnerable to an XML resou…
2019-01-01Pre-auth
EPSS7.5%
pct 93
7.5
CVE-2018-11796DEB
In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. Howev…
2018-01-01Pre-auth
EPSS6.9%
pct 93
4.4
CVE-2016-8734DEB
Apache Subversion's mod_dontdothat module and HTTP clients 1.4.0 through 1.8.16, and 1.9.0 thro…
2016-01-01
EPSS6.4%
pct 92
7.4
CVE-2021-23926DEB
The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to prote…
2021-01-01Pre-auth
EPSS6.3%
pct 92
7.5
CVE-2017-16932AST
parser.c in libxml2 before 2.9.5 does not prevent infinite recursion in parameter entities.
2017-01-01Pre-auth
EPSS5.9%
pct 92
4.3
CVE-2014-8090DEB
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, …
2014-01-01
EPSS5.6%
pct 91
4.3
CVE-2014-8080DEB
The REXML parser in Ruby 1.9.x before 1.9.3-p550, 2.0.x before 2.0.0-p594, and 2.1.x before 2.1…
2014-01-01
EPSS5.5%
pct 91
4.4
CVE-2019-5427DEB
c3p0 version < 0.9.5.4 may be exploited by a billion laughs attack when loading XML configurati…
2019-01-01
EPSS4.9%
pct 90
5.5
CVE-2017-5644DEB
Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of servi…
2017-01-01
EPSS4.6%
pct 90
7.5
CVE-2017-16931DEB
parser.c in libxml2 before 2.9.5 mishandles parameter-entity references because the NEXTL macro…
2017-01-01Pre-auth
EPSS4.5%
pct 90
7.5
CVE-2022-0217DEB
It was discovered that an internal Prosody library to load XML based on libexpat does not prope…
2022-01-01Pre-auth
EPSS4.4%
pct 90
5.3
CVE-2016-10149DEB
XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to…
2016-01-01Pre-auth
EPSS3.9%
pct 88
7.5
CVE-2011-1755DEB
jabberd2 before 2.2.14 does not properly detect recursion during entity expansion, which allows…
2011-01-01Pre-auth
EPSS3.7%
pct 88
9.8
CVE-2014-2228CVE
The XStream extension in HP Fortify SCA before 2.2 RC3 allows remote attackers to execute arbit…
2014-01-01Pre-auth
EPSS3.2%
pct 86
4.0
CVE-2013-4179DEB
The security group extension in OpenStack Compute (Nova) Grizzly 2013.1.3, Havana before havana…
2013-01-01
EPSS2.7%
pct 83
5.0
CVE-2014-3243DEB
SOAPpy 0.12.5 does not properly detect recursion during entity expansion, which allows remote a…
2014-01-01
EPSS2.7%
pct 83
6.5
CVE-2008-3281DEB
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an att…
2008-01-01Pre-auth
EPSS2.5%
pct 82
7.5
CVE-2015-9541DEB
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document th…
2015-01-01Pre-auth
EPSS2.5%
pct 82
9.8
CVE-2013-4335CVE
opOpenSocialPlugin 0.8.2.1, > 0.9.9.2, 0.9.13, 1.2.6: Multiple XML External Entity Injection Vu…
2013-01-01Pre-auth
EPSS2.5%
pct 82
7.5
CVE-2019-20104CVE
The OpenID client application in Atlassian Crowd before version 3.6.2, and from version 3.7.0 b…
2019-01-01Pre-auth
EPSS2.4%
pct 82
6.5
CVE-2013-6461DEB
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
2013-01-01Pre-auth
EPSS2.2%
pct 80
7.5
CVE-2012-6685DEB
Nokogiri before 1.5.4 is vulnerable to XXE attacks
2012-01-01Pre-auth
EPSS2.1%
pct 79
7.5
CVE-2022-25857DEB
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS)…
2022-01-01Pre-auth
EPSS2.1%
pct 79
6.5
CVE-2013-6460DEB
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
2013-01-01Pre-auth
EPSS2.1%
pct 79
7.5
CVE-2024-28757ANC
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of exte…
2024-01-01Pre-auth
EPSS2.0%
pct 78
3.7
CVE-2016-10040DEB
Stack-based buffer overflow in QXmlSimpleReader in Qt 4.8.5 allows remote attackers to cause a …
2016-01-01Pre-auth
EPSS1.9%
pct 77
7.5
CVE-2022-26662DEB
An XML Entity Expansion (XEE) issue was discovered in Tryton Application Platform (Server) 5.x …
2022-01-01Pre-auth
EPSS1.9%
pct 76
6.5
CVE-2021-3541AST
A flaw was found in libxml2. Exponential entity expansion attack its possible bypassing all exi…
2021-01-01
EPSS1.9%
pct 76
7.5
CVE-2011-3288CVE
Cisco Unified Presence before 8.5(4) does not properly detect recursion during entity expansion…
2011-01-01Pre-auth
EPSS1.8%
pct 75
4.3
CVE-2018-1307CVE
In Apache jUDDI 3.2 through 3.3.4, if using the WADL2Java or WSDL2Java classes, which parse a l…
2018-01-01Pre-auth
EPSS1.7%
pct 74
7.5
CVE-2019-15160CVE
The SweetXml (aka sweet_xml) package through 0.6.6 for Erlang and Elixir allows attackers to ca…
2019-01-01Pre-auth
EPSS1.7%
pct 73
7.5
CVE-2020-5227CVE
Feedgen (python feedgen) before 0.9.0 is susceptible to XML Denial of Service attacks. The *fee…
2020-01-01Pre-auth
EPSS1.6%
pct 73
6.5
CVE-2003-1564CVE
libxml2, possibly before 2.5.0, does not properly detect recursion during entity expansion, whi…
2003-01-01Pre-auth
EPSS1.6%
pct 72
7.5
CVE-2019-5442CVE
XML Entity Expansion (Billion Laughs Attack) on Pippo 1.12.0 results in Denial of Service.Entit…
2019-01-01Pre-auth
EPSS1.4%
pct 69
7.5
CVE-2022-33977DEB
untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and…
2022-01-01Pre-auth
EPSS1.4%
pct 68
6.5
CVE-2021-20464CVE
IBM Cognos Analytics PowerPlay (IBM Cognos Analytics 11.1.7, 11.2.0, and 11.1.7) could be vulne…
2021-01-01
EPSS1.3%
pct 66
9.1
CVE-2020-24590CVE
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML …
2020-01-01Pre-auth
EPSS1.3%
pct 65
Select a vulnerability on the left to open the preview.