Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2023-03-21 CVE-2022-43512 XXE vulnerability in Visam Vbase Automation Base
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
local
low complexity
visam CWE-611
5.5
2023-03-21 CVE-2022-46300 XXE vulnerability in Visam Vbase Automation Base
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
local
low complexity
visam CWE-611
5.5
2023-03-21 CVE-2018-25082 XXE vulnerability in Wechat SDK Python Project Wechat SDK Python
A vulnerability was found in zwczou WeChat SDK Python 0.3.0 and classified as critical.
network
low complexity
wechat-sdk-python-project CWE-611
critical
9.8
2023-03-21 CVE-2023-27874 XXE vulnerability in IBM Aspera Faspex 4.4.1/4.4.2
IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
8.8
2023-03-14 CVE-2023-26461 XXE vulnerability in SAP Netweaver Enterprise Portal 7.50
SAP NetWeaver allows (SAP Enterprise Portal) - version 7.50, allows an authenticated attacker with sufficient privileges to access the XML parser which can submit a crafted XML file which when parsed will enable them to access but not modify sensitive files and data.
network
low complexity
sap CWE-611
4.9
2023-03-09 CVE-2023-1288 XXE vulnerability in 3DS Enovia Live Collaboration
An XML External Entity injection (XXE) vulnerability in ENOVIA Live Collaboration V6R2013xE allows an attacker to read local files on the server.
network
low complexity
3ds CWE-611
7.5
2023-03-08 CVE-2023-27476 XXE vulnerability in Osgeo Owslib
OWSLib is a Python package for client programming with Open Geospatial Consortium (OGC) web service interface standards, and their related content models.
network
low complexity
osgeo CWE-611
7.5
2023-03-07 CVE-2023-27480 XXE vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-611
7.7
2023-02-27 CVE-2023-26043 XXE vulnerability in Geosolutionsgroup Geonode
GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data.
network
low complexity
geosolutionsgroup CWE-611
6.5
2023-02-24 CVE-2023-24189 XXE vulnerability in Bstek Urule 2.1.7
An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a crafted XML file to /urule/common/saveFile.
network
low complexity
bstek CWE-611
critical
9.8