CWE-611 · 1.303 kayıt
Improper Restriction of XML External Entity Reference
Bu sınıftaki CVE’ler
1.303 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2024-34102Silahlaştırılmış | XXE can expose crypt key and other secrets granting full admin accessadobe · commerce · CWE-611 | Kritik9,8 | KEV | %100,0 | 13 Haz 2024 |
99Hemen | CVE-2019-9670Silahlaştırılmış | mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, assynacor · zimbra collaboration suite · CWE-611 | Kritik9,8 | KEV | %100,0 | 29 May 2019 |
88Hemen | CVE-2025-2776Silahlaştırılmış | SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Kritik9,8 | KEV | %64,4 | 7 May 2025 |
87Hemen | CVE-2025-58360Silahlaştırılmış | GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap featuregeoserver · geoserver · CWE-611 | Kritik9,8 | KEV | %60,5 | 25 Kas 2025 |
73Bu hafta | CVE-2025-2775Silahlaştırılmış | SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Yüksek7,5 | KEV | %43,0 | 7 May 2025 |
69Bu hafta | CVE-2019-13608Silahlaştırılmış | Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.citrix · storefront server · CWE-611 | Yüksek7,5 | KEV | %30,0 | 29 Ağu 2019 |
68Bu hafta | CVE-2022-28219Silahlaştırılmış | Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.zohocorp · manageengine adaudit plus · CWE-611 | Kritik9,8 | — | %97,2 | 5 Nis 2022 |
67Bu hafta | CVE-2017-12629Kavram kanıtı | Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config Aapache · solr · CWE-611 | Kritik9,8 | — | %91,9 | 14 Eki 2017 |
65Bu hafta | CVE-2025-66516Silahlaştırılmış | Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affectedapache · tika · CWE-611 | Kritik9,8 | — | %88,1 | 4 Ara 2025 |
63Bu hafta | CVE-2016-9563Silahlaştırılmış | BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~tsap · netweaver application server java · CWE-611 | Orta6,5 | KEV | %24,2 | 22 Kas 2016 |
61Bu hafta | CVE-2024-22024Kavram kanıtı | An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) andivanti · connect secure · CWE-611 | Yüksek8,3 | — | %94,7 | 13 Şub 2024 |
61Bu hafta | CVE-2025-2777Kavram kanıtı | SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injectionsysaid · sysaid · CWE-611 | Kritik9,8 | — | %72,2 | 7 May 2025 |
61Bu hafta | CVE-2023-45727Silahlaştırılmış | Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1northgrid · proself · CWE-611 | Yüksek7,5 | KEV | %3,5 | 18 Eki 2023 |
58Planlayın | CVE-2024-38653Kavram kanıtı | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.ivanti · avalanche · CWE-611 | Yüksek7,5 | — | %92,0 | 13 Ağu 2024 |
57Planlayın | CVE-2023-44412İstismar yok | D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerabilitydlink · d-view 8 · CWE-611 | Yüksek8,2 | — | %83,7 | 2 May 2024 |
57Planlayın | CVE-2025-54254İstismar yok | Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)adobe · experience manager forms · CWE-611 | Yüksek8,6 | — | %77,5 | 5 Ağu 2025 |
56Planlayın | CVE-2022-2414Kavram kanıtı | Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.dogtagpki · dogtagpki · CWE-611 | Yüksek7,5 | — | %86,0 | 29 Tem 2022 |
56Planlayın | CVE-2021-37425Kavram kanıtı | Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reaaltova · mobiletogether server · CWE-611 | Kritik9,1 | — | %66,3 | 10 Ağu 2021 |
55Planlayın | CVE-2016-4264Kavram kanıtı | The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitraradobe · coldfusion · CWE-611 | Yüksek8,6 | — | %69,0 | 1 Eyl 2016 |
52Planlayın | CVE-2021-29447Kavram kanıtı | WordPress Authenticated XXE attack when installation is running PHP 8wordpress · wordpress · CWE-611 | Orta6,5 | — | %85,7 | 15 Nis 2021 |
52Planlayın | CVE-2020-27858İstismar yok | This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.arcserve · d2d · CWE-611 | Yüksek7,5 | — | %73,8 | 20 Oca 2021 |
52Planlayın | CVE-2020-11991Kavram kanıtı | When using the StreamGenerator, the code parse a user-provided XML.apache · cocoon · CWE-611 | Yüksek7,5 | — | %72,5 | 11 Eyl 2020 |
51Planlayın | CVE-2020-17408İstismar yok | This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.nec · expresscluster x · CWE-611 | Yüksek7,5 | — | %69,3 | 10 Eyl 2020 |
51Planlayın | CVE-2012-3363Kavram kanıtı | Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows rezend · zend framework · CWE-611 | Kritik9,1 | — | %50,2 | 13 Şub 2013 |
51Planlayın | CVE-2019-7442Kavram kanıtı | An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remotcyberark · enterprise password vault · CWE-611 | Kritik9,8 | — | %40,0 | 8 May 2019 |
- CVE-2024-3410299Hemen
XXE can expose crypt key and other secrets granting full admin access
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100adobe · commerce13 Haz 2024
- CVE-2019-967099Hemen
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100synacor · zimbra collaboration suite29 May 2019
- CVE-2025-277688Hemen
SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %64sysaid · sysaid7 May 2025
- CVE-2025-5836087Hemen
GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61geoserver · geoserver25 Kas 2025
- CVE-2025-277573Bu hafta
SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %43sysaid · sysaid7 May 2025
- CVE-2019-1360869Bu hafta
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %30citrix · storefront server29 Ağu 2019
- CVE-2022-2821968Bu hafta
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
KritikCVSS 9,8SilahlaştırılmışEPSS %97zohocorp · manageengine adaudit plus5 Nis 2022
- CVE-2017-1262967Bu hafta
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A
KritikCVSS 9,8Kavram kanıtıEPSS %92apache · solr14 Eki 2017
- CVE-2025-6651665Bu hafta
Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected
KritikCVSS 9,8SilahlaştırılmışEPSS %88apache · tika4 Ara 2025
- CVE-2016-956363Bu hafta
BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %24sap · netweaver application server java22 Kas 2016
- CVE-2024-2202461Bu hafta
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and
YüksekCVSS 8,3Kavram kanıtıEPSS %95ivanti · connect secure13 Şub 2024
- CVE-2025-277761Bu hafta
SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
KritikCVSS 9,8Kavram kanıtıEPSS %72sysaid · sysaid7 May 2025
- CVE-2023-4572761Bu hafta
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %4northgrid · proself18 Eki 2023
- CVE-2024-3865358Planlayın
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
YüksekCVSS 7,5Kavram kanıtıEPSS %92ivanti · avalanche13 Ağu 2024
- CVE-2023-4441257Planlayın
D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability
YüksekCVSS 8,2İstismar yokEPSS %84dlink · d-view 82 May 2024
- CVE-2025-5425457Planlayın
Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)
YüksekCVSS 8,6İstismar yokEPSS %77adobe · experience manager forms5 Ağu 2025
- CVE-2022-241456Planlayın
Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.
YüksekCVSS 7,5Kavram kanıtıEPSS %86dogtagpki · dogtagpki29 Tem 2022
- CVE-2021-3742556Planlayın
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea
KritikCVSS 9,1Kavram kanıtıEPSS %66altova · mobiletogether server10 Ağu 2021
- CVE-2016-426455Planlayın
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar
YüksekCVSS 8,6Kavram kanıtıEPSS %69adobe · coldfusion1 Eyl 2016
- CVE-2021-2944752Planlayın
WordPress Authenticated XXE attack when installation is running PHP 8
OrtaCVSS 6,5Kavram kanıtıEPSS %86wordpress · wordpress15 Nis 2021
- CVE-2020-2785852Planlayın
This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.
YüksekCVSS 7,5İstismar yokEPSS %74arcserve · d2d20 Oca 2021
- CVE-2020-1199152Planlayın
When using the StreamGenerator, the code parse a user-provided XML.
YüksekCVSS 7,5Kavram kanıtıEPSS %72apache · cocoon11 Eyl 2020
- CVE-2020-1740851Planlayın
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.
YüksekCVSS 7,5İstismar yokEPSS %69nec · expresscluster x10 Eyl 2020
- CVE-2012-336351Planlayın
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re
KritikCVSS 9,1Kavram kanıtıEPSS %50zend · zend framework13 Şub 2013
- CVE-2019-744251Planlayın
An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot
KritikCVSS 9,8Kavram kanıtıEPSS %40cyberark · enterprise password vault8 May 2019