İçeriğe atla
Noroxi

CWE-611 · 1.303 kayıt

Improper Restriction of XML External Entity Reference

Bu sınıftaki CVE’ler

1.303 kayıt

  • XXE can expose crypt key and other secrets granting full admin access

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    adobe · commerce13 Haz 2024

  • mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    synacor · zimbra collaboration suite29 May 2019

  • SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %64

    sysaid · sysaid7 May 2025

  • GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %61

    geoserver · geoserver25 Kas 2025

  • CVE-2025-2775
    73Bu hafta

    SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %43

    sysaid · sysaid7 May 2025

  • CVE-2019-13608
    69Bu hafta

    Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %30

    citrix · storefront server29 Ağu 2019

  • CVE-2022-28219
    68Bu hafta

    Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.

    KritikCVSS 9,8SilahlaştırılmışEPSS %97

    zohocorp · manageengine adaudit plus5 Nis 2022

  • CVE-2017-12629
    67Bu hafta

    Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction with use of a Config A

    KritikCVSS 9,8Kavram kanıtıEPSS %92

    apache · solr14 Eki 2017

  • CVE-2025-66516
    65Bu hafta

    Apache Tika core, Apache Tika parsers, Apache Tika PDF parser module: Update to CVE-2025-54988 to expand scope of artifacts affected

    KritikCVSS 9,8SilahlaştırılmışEPSS %88

    apache · tika4 Ara 2025

  • CVE-2016-9563
    63Bu hafta

    BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via the sap.com~t

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %24

    sap · netweaver application server java22 Kas 2016

  • CVE-2024-22024
    61Bu hafta

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and

    YüksekCVSS 8,3Kavram kanıtıEPSS %95

    ivanti · connect secure13 Şub 2024

  • CVE-2025-2777
    61Bu hafta

    SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection

    KritikCVSS 9,8Kavram kanıtıEPSS %72

    sysaid · sysaid7 May 2025

  • CVE-2023-45727
    61Bu hafta

    Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %4

    northgrid · proself18 Eki 2023

  • CVE-2024-38653
    58Planlayın

    XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

    YüksekCVSS 7,5Kavram kanıtıEPSS %92

    ivanti · avalanche13 Ağu 2024

  • CVE-2023-44412
    57Planlayın

    D-Link D-View addDv7Probe XML External Entity Processing Information Disclosure Vulnerability

    YüksekCVSS 8,2İstismar yokEPSS %84

    dlink · d-view 82 May 2024

  • CVE-2025-54254
    57Planlayın

    Adobe Experience Manager | Improper Restriction of XML External Entity Reference ('XXE') (CWE-611)

    YüksekCVSS 8,6İstismar yokEPSS %77

    adobe · experience manager forms5 Ağu 2025

  • CVE-2022-2414
    56Planlayın

    Access to external entities when parsing XML documents can lead to XML external entity (XXE) attacks.

    YüksekCVSS 7,5Kavram kanıtıEPSS %86

    dogtagpki · dogtagpki29 Tem 2022

  • CVE-2021-37425
    56Planlayın

    Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or rea

    KritikCVSS 9,1Kavram kanıtıEPSS %66

    altova · mobiletogether server10 Ağu 2021

  • CVE-2016-4264
    55Planlayın

    The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrar

    YüksekCVSS 8,6Kavram kanıtıEPSS %69

    adobe · coldfusion1 Eyl 2016

  • CVE-2021-29447
    52Planlayın

    WordPress Authenticated XXE attack when installation is running PHP 8

    OrtaCVSS 6,5Kavram kanıtıEPSS %86

    wordpress · wordpress15 Nis 2021

  • CVE-2020-27858
    52Planlayın

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of CA Arcserve D2D 16.5.

    YüksekCVSS 7,5İstismar yokEPSS %74

    arcserve · d2d20 Oca 2021

  • CVE-2020-11991
    52Planlayın

    When using the StreamGenerator, the code parse a user-provided XML.

    YüksekCVSS 7,5Kavram kanıtıEPSS %72

    apache · cocoon11 Eyl 2020

  • CVE-2020-17408
    51Planlayın

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1.

    YüksekCVSS 7,5İstismar yokEPSS %69

    nec · expresscluster x10 Eyl 2020

  • CVE-2012-3363
    51Planlayın

    Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows re

    KritikCVSS 9,1Kavram kanıtıEPSS %50

    zend · zend framework13 Şub 2013

  • CVE-2019-7442
    51Planlayın

    An XML external entity (XXE) vulnerability in the Password Vault Web Access (PVWA) of CyberArk Enterprise Password Vault <=10.7 allows remot

    KritikCVSS 9,8Kavram kanıtıEPSS %40

    cyberark · enterprise password vault8 May 2019

Tüm zafiyet sınıfları