Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2023-03-24 CVE-2023-28151 XXE vulnerability in Independentsoft Jspreadsheet
An issue was discovered in Independentsoft JSpreadsheet before 1.1.110.
network
low complexity
independentsoft CWE-611
critical
9.8
2023-03-24 CVE-2023-28152 XXE vulnerability in Independentsoft Jword
An issue was discovered in Independentsoft JWord before 1.1.110.
network
low complexity
independentsoft CWE-611
critical
9.8
2023-03-22 CVE-2023-28685 XXE vulnerability in Jenkins Absint A3
Jenkins AbsInt a³ Plugin 1.1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
7.1
2023-03-21 CVE-2022-43512 XXE vulnerability in Visam Vbase Automation Base
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
local
low complexity
visam CWE-611
5.5
2023-03-21 CVE-2022-46300 XXE vulnerability in Visam Vbase Automation Base
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
local
low complexity
visam CWE-611
5.5
2023-03-21 CVE-2018-25082 XXE vulnerability in Wechat SDK Python Project Wechat SDK Python
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical.
network
low complexity
wechat-sdk-python-project CWE-611
critical
9.8
2023-03-09 CVE-2023-1288 XXE vulnerability in 3DS Enovia Live Collaboration
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
network
low complexity
3ds CWE-611
7.5
2023-02-27 CVE-2023-26043 XXE vulnerability in Geosolutionsgroup Geonode
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data.
network
low complexity
geosolutionsgroup CWE-611
6.5
2023-02-24 CVE-2023-24189 XXE vulnerability in Bstek Urule 2.1.7
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.
network
low complexity
bstek CWE-611
critical
9.8
2023-02-22 CVE-2023-20855 XXE vulnerability in VMWare Vrealize Automation and Vrealize Orchestrator
VMware vRealize Orchestrator contains an XML External Entity (XXE) vulnerability.
network
low complexity
vmware CWE-611
8.8