Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2022-05-03 CVE-2022-1331 XXE vulnerability in Deltaww Dmars
In four instances DMARS (All versions prior to v2.1.10.24) does not properly restrict references of XML external entities while processing specific project files, which may allow unauthorized information disclosure.
local
low complexity
deltaww CWE-611
5.5
2022-05-03 CVE-2022-21949 XXE vulnerability in Opensuse Open Build Service
A Improper Restriction of XML External Entity Reference vulnerability in SUSE Open Build Service allows remote attackers to reference external entities in certain operations.
network
low complexity
opensuse CWE-611
8.8
2022-04-30 CVE-2022-29265 XXE vulnerability in Apache Nifi
Multiple components in Apache NiFi 0.0.1 to 1.16.0 do not restrict XML External Entity references in the default configuration.
network
low complexity
apache CWE-611
7.5
2022-04-28 CVE-2022-24898 XXE vulnerability in Xwiki Commons
org.xwiki.commons:xwiki-commons-xml is a common module used by other XWiki top level projects.
network
low complexity
xwiki CWE-611
4.9
2022-04-21 CVE-2022-0272 XXE vulnerability in Detekt
Improper Restriction of XML External Entity Reference in GitHub repository detekt/detekt prior to 1.20.0.
network
low complexity
detekt CWE-611
critical
9.8
2022-04-20 CVE-2021-43990 XXE vulnerability in Fanuc Roboguide 9.40083.00.05
The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.
network
high complexity
fanuc CWE-611
5.3
2022-04-13 CVE-2022-0221 XXE vulnerability in Schneider-Electric Scadapack Workbench 6.6.8A
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench.
local
low complexity
schneider-electric CWE-611
5.5
2022-04-05 CVE-2022-28219 XXE vulnerability in Zohocorp Manageengine Adaudit Plus
Cewolf in Zoho ManageEngine ADAudit Plus before 7060 is vulnerable to an unauthenticated XXE attack that leads to Remote Code Execution.
network
low complexity
zohocorp CWE-611
critical
9.8
2022-04-01 CVE-2022-1018 XXE vulnerability in Rockwellautomation products
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file.
local
low complexity
rockwellautomation CWE-611
5.5
2022-03-30 CVE-2021-33208 XXE vulnerability in Softwareag Mashzone Nextgen 10.7
The "Register an Ehcache Configuration File" admin feature in MashZone NextGen through 10.7 GA allows XXE attacks via a malicious XML configuration file.
network
low complexity
softwareag CWE-611
7.2