Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2023-01-26 CVE-2023-24443 XXE vulnerability in Jenkins Testcomplete Support
Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins CWE-611
critical
9.8
2023-01-17 CVE-2023-22624 XXE vulnerability in Zohocorp Manageengine Exchange Reporter Plus
Zoho ManageEngine Exchange Reporter Plus before 5708 allows attackers to conduct XXE attacks.
network
low complexity
zohocorp CWE-611
7.5
2023-01-15 CVE-2023-23595 XXE vulnerability in Bluecatnetworks Device Registration Portal 2.2
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files.
network
low complexity
bluecatnetworks CWE-611
7.5
2023-01-09 CVE-2021-4311 XXE vulnerability in Talend Open Studio
A vulnerability classified as problematic was found in Talend Open Studio for MDM.
network
low complexity
talend CWE-611
critical
9.8
2023-01-07 CVE-2015-10029 XXE vulnerability in Simplexrd Project Simplexrd
A vulnerability classified as problematic was found in kelvinmo simplexrd up to 3.1.0.
network
low complexity
simplexrd-project CWE-611
critical
9.8
2023-01-06 CVE-2016-15011 XXE vulnerability in E-Contract Dssp
A vulnerability classified as problematic was found in e-Contract dssp up to 1.3.1.
network
low complexity
e-contract CWE-611
critical
9.8
2023-01-05 CVE-2020-36641 XXE vulnerability in Gturri Axmlrpc
A vulnerability classified as problematic was found in gturri aXMLRPC up to 1.12.0.
network
low complexity
gturri CWE-611
critical
9.8
2023-01-05 CVE-2020-36640 XXE vulnerability in Bonitasoft Webservice Connector
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0.
network
low complexity
bonitasoft CWE-611
critical
9.8
2022-12-30 CVE-2017-20151 XXE vulnerability in Itextpdf Rups
A vulnerability classified as problematic was found in iText RUPS.
network
low complexity
itextpdf CWE-611
critical
9.8
2022-12-29 CVE-2021-4295 XXE vulnerability in Healthit Code-Validator-Api
A vulnerability classified as problematic was found in ONC code-validator-api up to 1.0.30.
network
low complexity
healthit CWE-611
critical
9.8