CWE-611 · 1 303 записей
Improper Restriction of XML External Entity Reference
CVE этого класса
1 303 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2024-34102Готовый эксплойт | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Критическая9,8 | KEV | 100,0 % | 13 июн. 2024 г. |
99Срочно | CVE-2019-9670Готовый эксплойт | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, assynacor · zimbra collaboration suite · CWE-611 | Критическая9,8 | KEV | 100,0 % | 29 мая 2019 г. |
88Срочно | CVE-2025-2776Готовый эксплойт | SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Критическая9,8 | KEV | 64,4 % | 7 мая 2025 г. |
87Срочно | CVE-2025-58360Готовый эксплойт | GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap featuregeoserver · geoserver · CWE-611 | Критическая9,8 | KEV | 60,5 % | 25 нояб. 2025 г. |
73На этой неделе | CVE-2025-2775Готовый эксплойт | SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Высокая7,5 | KEV | 43,0 % | 7 мая 2025 г. |
69На этой неделе | CVE-2019-13608Готовый эксплойт | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.citrix · storefront server · CWE-611 | Высокая7,5 | KEV | 30,0 % | 29 авг. 2019 г. |
68На этой неделе | CVE-2022-28219Готовый эксплойт | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.zohocorp · manageengine adaudit plus · CWE-611 | Критическая9,8 | — | 97,2 % | 5 апр. 2022 г. |
67На этой неделе | CVE-2017-12629Proof of concept | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config Aapache · solr · CWE-611 | Критическая9,8 | — | 91,9 % | 14 окт. 2017 г. |
65На этой неделе | CVE-2025-66516Готовый эксплойт | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedapache · tika · CWE-611 | Критическая9,8 | — | 88,1 % | 4 дек. 2025 г. |
63На этой неделе | CVE-2016-9563Готовый эксплойт | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tsap · netweaver application server java · CWE-611 | Средняя6,5 | KEV | 24,2 % | 22 нояб. 2016 г. |
61На этой неделе | CVE-2024-22024Proof of concept | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) andivanti · connect secure · CWE-611 | Высокая8,3 | — | 94,7 % | 13 февр. 2024 г. |
61На этой неделе | CVE-2025-2777Proof of concept | SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Критическая9,8 | — | 72,2 % | 7 мая 2025 г. |
61На этой неделе | CVE-2023-45727Готовый эксплойт | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1northgrid · proself · CWE-611 | Высокая7,5 | KEV | 3,5 % | 18 окт. 2023 г. |
58В плане | CVE-2024-38653Proof of concept | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.ivanti · avalanche · CWE-611 | Высокая7,5 | — | 92,0 % | 13 авг. 2024 г. |
57В плане | CVE-2023-44412Эксплойта нет | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerabilitydlink · d-view 8 · CWE-611 | Высокая8,2 | — | 83,7 % | 2 мая 2024 г. |
57В плане | CVE-2025-54254Эксплойта нет | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)adobe · experience manager forms · CWE-611 | Высокая8,6 | — | 77,5 % | 5 авг. 2025 г. |
56В плане | CVE-2022-2414Proof of concept | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.dogtagpki · dogtagpki · CWE-611 | Высокая7,5 | — | 86,0 % | 29 июл. 2022 г. |
56В плане | CVE-2021-37425Proof of concept | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reaaltova · mobiletogether server · CWE-611 | Критическая9,1 | — | 66,3 % | 10 авг. 2021 г. |
55В плане | CVE-2016-4264Proof of concept | The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitraradobe · coldfusion · CWE-611 | Высокая8,6 | — | 69,0 % | 1 сент. 2016 г. |
52В плане | CVE-2021-29447Proof of concept | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Средняя6,5 | — | 85,7 % | 15 апр. 2021 г. |
52В плане | CVE-2020-27858Эксплойта нет | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.arcserve · d2d · CWE-611 | Высокая7,5 | — | 73,8 % | 20 янв. 2021 г. |
52В плане | CVE-2020-11991Proof of concept | When using the StreamGenerator, the code parse a user-provided XML.apache · cocoon · CWE-611 | Высокая7,5 | — | 72,5 % | 11 сент. 2020 г. |
51В плане | CVE-2020-17408Эксплойта нет | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | Высокая7,5 | — | 69,3 % | 10 сент. 2020 г. |
51В плане | CVE-2012-3363Proof of concept | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows rezend · zend framework · CWE-611 | Критическая9,1 | — | 50,2 % | 13 февр. 2013 г. |
51В плане | CVE-2019-7442Proof of concept | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remotcyberark · enterprise password vault · CWE-611 | Критическая9,8 | — | 40,0 % | 8 мая 2019 г. |
- CVE-2024-3410299Срочно
XXE can expose crypt key and other secrets granting full admin access
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · commerce13 июн. 2024 г.
- CVE-2019-967099Срочно
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %synacor · zimbra collaboration suite29 мая 2019 г.
- CVE-2025-277688Срочно
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %sysaid · sysaid7 мая 2025 г.
- CVE-2025-5836087Срочно
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %geoserver · geoserver25 нояб. 2025 г.
- CVE-2025-277573На этой неделе
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 43 %sysaid · sysaid7 мая 2025 г.
- CVE-2019-1360869На этой неделе
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 30 %citrix · storefront server29 авг. 2019 г.
- CVE-2022-2821968На этой неделе
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %zohocorp · manageengine adaudit plus5 апр. 2022 г.
- CVE-2017-1262967На этой неделе
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A
КритическаяCVSS 9,8Proof of conceptEPSS 92 %apache · solr14 окт. 2017 г.
- CVE-2025-6651665На этой неделе
Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
КритическаяCVSS 9,8Готовый эксплойтEPSS 88 %apache · tika4 дек. 2025 г.
- CVE-2016-956363На этой неделе
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 24 %sap · netweaver application server java22 нояб. 2016 г.
- CVE-2024-2202461На этой неделе
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and
ВысокаяCVSS 8,3Proof of conceptEPSS 95 %ivanti · connect secure13 февр. 2024 г.
- CVE-2025-277761На этой неделе
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
КритическаяCVSS 9,8Proof of conceptEPSS 72 %sysaid · sysaid7 мая 2025 г.
- CVE-2023-4572761На этой неделе
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 4 %northgrid · proself18 окт. 2023 г.
- CVE-2024-3865358В плане
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
ВысокаяCVSS 7,5Proof of conceptEPSS 92 %ivanti · avalanche13 авг. 2024 г.
- CVE-2023-4441257В плане
D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability
ВысокаяCVSS 8,2Эксплойта нетEPSS 84 %dlink · d-view 82 мая 2024 г.
- CVE-2025-5425457В плане
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
ВысокаяCVSS 8,6Эксплойта нетEPSS 77 %adobe · experience manager forms5 авг. 2025 г.
- CVE-2022-241456В плане
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.
ВысокаяCVSS 7,5Proof of conceptEPSS 86 %dogtagpki · dogtagpki29 июл. 2022 г.
- CVE-2021-3742556В плане
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea
КритическаяCVSS 9,1Proof of conceptEPSS 66 %altova · mobiletogether server10 авг. 2021 г.
- CVE-2016-426455В плане
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar
ВысокаяCVSS 8,6Proof of conceptEPSS 69 %adobe · coldfusion1 сент. 2016 г.
- CVE-2021-2944752В плане
WordPress Authenticated XXE attack when installation is running PHP 8
СредняяCVSS 6,5Proof of conceptEPSS 86 %wordpress · wordpress15 апр. 2021 г.
- CVE-2020-2785852В плане
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.
ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %arcserve · d2d20 янв. 2021 г.
- CVE-2020-1199152В плане
When using the StreamGenerator, the code parse a user-provided XML.
ВысокаяCVSS 7,5Proof of conceptEPSS 72 %apache · cocoon11 сент. 2020 г.
- CVE-2020-1740851В плане
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %nec · expresscluster x10 сент. 2020 г.
- CVE-2012-336351В плане
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re
КритическаяCVSS 9,1Proof of conceptEPSS 50 %zend · zend framework13 февр. 2013 г.
- CVE-2019-744251В плане
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot
КритическаяCVSS 9,8Proof of conceptEPSS 40 %cyberark · enterprise password vault8 мая 2019 г.