Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2024-11-15 CVE-2021-1483 A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an affected system. This vulnerability is due to improper handling of XML External Entity (XXE) entries when the affected software parses certain XML files.
network
low complexity
CWE-611
6.4
2024-11-15 CVE-2024-39726 XXE vulnerability in IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2/7.0.3
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.2
2024-11-15 CVE-2021-3902 XXE vulnerability in Dompdf Project Dompdf
An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks.
network
low complexity
dompdf-project CWE-611
critical
9.8
2024-11-08 CVE-2024-10839 XXE vulnerability in Zohocorp Manageengine Sharepoint Manager Plus
Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option.
network
low complexity
zohocorp CWE-611
8.1
2024-11-04 CVE-2024-45086 XXE vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.5
2024-11-04 CVE-2024-51136 XXE vulnerability in Openimaj 1.3.10
An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML file.
network
low complexity
openimaj CWE-611
critical
9.8
2024-10-28 CVE-2024-50442 XXE vulnerability in Royal-Elementor-Addons Royal Elementor Addons
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons allows XML Injection.This issue affects Royal Elementor Addons: from n/a through 1.3.980.
network
low complexity
royal-elementor-addons CWE-611
7.2
2024-10-16 CVE-2024-45072 XXE vulnerability in IBM Websphere Application Server
IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
5.5
2024-10-16 CVE-2024-4184 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0
2024-10-16 CVE-2024-4189 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0