Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2025-02-20 CVE-2024-49781 IBM OpenPages with Watson 8.3 and 9.0 IBM OpenPages is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
CWE-611
7.1
2025-02-19 CVE-2023-47160 IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
CWE-611
8.2
2025-02-12 CVE-2025-1225 A vulnerability, which was classified as problematic, has been found in ywoa up to 2024.07.03.
network
low complexity
CWE-611
6.3
2025-02-06 CVE-2024-54171 IBM EntireX 11.1 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
CWE-611
7.1
2025-02-05 CVE-2024-49352 IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, 12.0.2, 12.0.3, and 12.0.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
CWE-611
7.1
2024-12-20 CVE-2024-56356 XXE vulnerability in Jetbrains Teamcity
In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack
network
low complexity
jetbrains CWE-611
7.1
2024-12-10 CVE-2024-49704 A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2), COMOS V10.4.4.1 (All versions < V10.4.4.1.21).
local
low complexity
CWE-611
5.5
2024-12-10 CVE-2024-54005 A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V10.4.3 (All versions < V10.4.3.0.47), COMOS V10.4.4 (All versions < V10.4.4.2), COMOS V10.4.4.1 (All versions < V10.4.4.1.21).
local
high complexity
CWE-611
5.1
2024-11-26 CVE-2024-11622 XXE vulnerability in HPE Insight Remote Support 7.12/7.12.0.529/7.12.0.545
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
network
low complexity
hpe CWE-611
7.5
2024-11-26 CVE-2024-53674 XXE vulnerability in HPE Insight Remote Support 7.12/7.12.0.529/7.12.0.545
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.
network
low complexity
hpe CWE-611
7.5