Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2023-01-05 CVE-2020-36641 XXE vulnerability in Gturri Axmlrpc
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0.
network
low complexity
gturri CWE-611
critical
9.8
2023-01-05 CVE-2020-36640 XXE vulnerability in Bonitasoft Webservice Connector
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0.
network
low complexity
bonitasoft CWE-611
critical
9.8
2022-12-30 CVE-2017-20151 XXE vulnerability in Itextpdf Rups
A vulnerability classified as problematic was found in iText RUPS.
network
low complexity
itextpdf CWE-611
critical
9.8
2022-12-29 CVE-2021-4295 XXE vulnerability in Healthit Code-Validator-Api
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30.
network
low complexity
healthit CWE-611
critical
9.8
2022-12-28 CVE-2022-4818 XXE vulnerability in Talend Open Studio for MDM
A vulnerability was found in Talend Open Studio for MDM.
network
low complexity
talend CWE-611
4.3
2022-12-28 CVE-2022-41967 XXE vulnerability in Hypera Dragonfly 0.3.0Snapshot
Dragonfly is a Java runtime dependency management library.
network
low complexity
hypera CWE-611
7.5
2022-12-18 CVE-2022-4607 XXE vulnerability in TUM OGC web Feature Service
A vulnerability was found in 3D City Database OGC Web Feature Service up to 5.2.0.
network
low complexity
tum CWE-611
critical
9.8
2022-12-18 CVE-2022-47514 An XML external entity (XXE) injection vulnerability in XML-RPC.NET before 2.5.0 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, as demonstrated by a pingback.aspx POST request.
network
low complexity
CWE-611
8.8
2022-12-16 CVE-2022-25628 XXE vulnerability in Broadcom Symantec Identity Governance and Administration 14.3/14.4
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
network
low complexity
broadcom CWE-611
8.8
2022-12-12 CVE-2022-37911 XXE vulnerability in Arubanetworks Arubaos and Sd-Wan
Due to improper restrictions on XML entities multiple vulnerabilities exist in the command line interface of ArubaOS.
network
low complexity
arubanetworks CWE-611
5.5