Перейти к содержимому
Noroxi

CWE-611 · 1 303 записей

Improper Restriction of XML External Entity Reference

CVE этого класса

1 303 записей

  • CVE-2024-34102
    99Срочно

    XXE can expose crypt key and other secrets granting full admin access

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    adobe · commerce13 июн. 2024 г.

  • CVE-2019-9670
    99Срочно

    mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    synacor · zimbra collaboration suite29 мая 2019 г.

  • CVE-2025-2776
    88Срочно

    SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %

    sysaid · sysaid7 мая 2025 г.

  • CVE-2025-58360
    87Срочно

    GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 61 %

    geoserver · geoserver25 нояб. 2025 г.

  • CVE-2025-2775
    73На этой неделе

    SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 43 %

    sysaid · sysaid7 мая 2025 г.

  • CVE-2019-13608
    69На этой неделе

    Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 30 %

    citrix · storefront server29 авг. 2019 г.

  • CVE-2022-28219
    68На этой неделе

    Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

    КритическаяCVSS 9,8Готовый эксплойтEPSS 97 %

    zohocorp · manageengine adaudit plus5 апр. 2022 г.

  • CVE-2017-12629
    67На этой неделе

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A

    КритическаяCVSS 9,8Proof of conceptEPSS 92 %

    apache · solr14 окт. 2017 г.

  • CVE-2025-66516
    65На этой неделе

    Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected

    КритическаяCVSS 9,8Готовый эксплойтEPSS 88 %

    apache · tika4 дек. 2025 г.

  • CVE-2016-9563
    63На этой неделе

    BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t

    СредняяCVSS 6,5KEVГотовый эксплойтEPSS 24 %

    sap · netweaver application server java22 нояб. 2016 г.

  • CVE-2024-22024
    61На этой неделе

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and

    ВысокаяCVSS 8,3Proof of conceptEPSS 95 %

    ivanti · connect secure13 февр. 2024 г.

  • CVE-2025-2777
    61На этой неделе

    SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

    КритическаяCVSS 9,8Proof of conceptEPSS 72 %

    sysaid · sysaid7 мая 2025 г.

  • CVE-2023-45727
    61На этой неделе

    Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 4 %

    northgrid · proself18 окт. 2023 г.

  • CVE-2024-38653
    58В плане

    XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

    ВысокаяCVSS 7,5Proof of conceptEPSS 92 %

    ivanti · avalanche13 авг. 2024 г.

  • CVE-2023-44412
    57В плане

    D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability

    ВысокаяCVSS 8,2Эксплойта нетEPSS 84 %

    dlink · d-view 82 мая 2024 г.

  • CVE-2025-54254
    57В плане

    Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

    ВысокаяCVSS 8,6Эксплойта нетEPSS 77 %

    adobe · experience manager forms5 авг. 2025 г.

  • CVE-2022-2414
    56В плане

    Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.

    ВысокаяCVSS 7,5Proof of conceptEPSS 86 %

    dogtagpki · dogtagpki29 июл. 2022 г.

  • CVE-2021-37425
    56В плане

    Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea

    КритическаяCVSS 9,1Proof of conceptEPSS 66 %

    altova · mobiletogether server10 авг. 2021 г.

  • CVE-2016-4264
    55В плане

    The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar

    ВысокаяCVSS 8,6Proof of conceptEPSS 69 %

    adobe · coldfusion1 сент. 2016 г.

  • CVE-2021-29447
    52В плане

    WordPress Authenticated XXE attack when installation is running PHP 8

    СредняяCVSS 6,5Proof of conceptEPSS 86 %

    wordpress · wordpress15 апр. 2021 г.

  • CVE-2020-27858
    52В плане

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 74 %

    arcserve · d2d20 янв. 2021 г.

  • CVE-2020-11991
    52В плане

    When using the StreamGenerator, the code parse a user-provided XML.

    ВысокаяCVSS 7,5Proof of conceptEPSS 72 %

    apache · cocoon11 сент. 2020 г.

  • CVE-2020-17408
    51В плане

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 69 %

    nec · expresscluster x10 сент. 2020 г.

  • CVE-2012-3363
    51В плане

    Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re

    КритическаяCVSS 9,1Proof of conceptEPSS 50 %

    zend · zend framework13 февр. 2013 г.

  • CVE-2019-7442
    51В плане

    An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot

    КритическаяCVSS 9,8Proof of conceptEPSS 40 %

    cyberark · enterprise password vault8 мая 2019 г.

Все классы уязвимостей