Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2024-4690 XXE vulnerability in Microfocus Application Automation Tools
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automation Tools: 24.1.0 and below.
network
low complexity
microfocus CWE-611
8.0
2024-10-09 CVE-2024-39586 XXE vulnerability in Dell EMC Appsync
Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability.
low complexity
dell CWE-611
4.3
2024-09-23 CVE-2024-46985 XXE vulnerability in Dataease
DataEase is an open source data visualization analysis tool.
network
low complexity
dataease CWE-611
7.5
2024-09-19 CVE-2024-46984 XXE vulnerability in Gematik Reference Validator
The reference validator is a tool to perform advanced validation of FHIR resources for TI applications and interoperability standards.
network
low complexity
gematik CWE-611
critical
9.8
2024-09-16 CVE-2024-7098 XXE vulnerability in SFS Winsure
Improper Restriction of XML External Entity Reference vulnerability in SFS Consulting ww.Winsure allows XML Injection.This issue affects ww.Winsure: before 4.6.2.
network
low complexity
sfs CWE-611
critical
9.8
2024-09-10 CVE-2023-37233 XXE vulnerability in Loftware Spectrum
Loftware Spectrum before 4.6 HF14 allows authenticated XXE attacks.
network
low complexity
loftware CWE-611
8.8
2024-08-30 CVE-2024-45490 XXE vulnerability in Libexpat Project Libexpat
An issue was discovered in libexpat before 2.6.3.
network
low complexity
libexpat-project CWE-611
7.5
2024-08-28 CVE-2024-45048 XXE vulnerability in PHPoffice PHPspreadsheet
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files.
network
low complexity
phpoffice CWE-611
6.5
2024-08-14 CVE-2024-38653 XXE vulnerability in Ivanti Avalanche
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
network
low complexity
ivanti CWE-611
7.5
2024-08-08 CVE-2024-6893 XXE vulnerability in Journyx 11.5.4
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities.
network
low complexity
journyx CWE-611
7.5