Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2021-10-31 CVE-2020-26705 XXE vulnerability in Easyxml Project Easyxml 0.5.0
The parseXML function in Easy-XML 0.5.0 was discovered to have a XML External Entity (XXE) vulnerability which allows for an attacker to expose sensitive data or perform a denial of service (DOS) via a crafted external entity entered into the XML content as input.
network
low complexity
easyxml-project CWE-611
critical
9.1
2021-10-31 CVE-2020-25911 XXE vulnerability in Modx Revolution 2.7.3
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
network
low complexity
modx CWE-611
critical
9.1
2021-10-31 CVE-2020-25912 XXE vulnerability in Getsymphony Symphony 2.7.10
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
network
low complexity
getsymphony CWE-611
critical
9.1
2021-10-19 CVE-2021-3869 XXE vulnerability in Stanford Corenlp
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
network
low complexity
stanford CWE-611
7.5
2021-10-15 CVE-2021-3878 XXE vulnerability in Stanford Corenlp
corenlp is vulnerable to Improper Restriction of XML External Entity Reference
network
low complexity
stanford CWE-611
critical
9.8
2021-10-14 CVE-2020-19954 XXE vulnerability in S-Cms 3.0
An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.
network
low complexity
s-cms CWE-611
7.5
2021-10-13 CVE-2021-20801 XXE vulnerability in Cybozu Remote Service Manager 3.1.8/3.1.9
Cybozu Remote Service 3.1.8 to 3.1.9 allows a remote authenticated attacker to conduct XML External Entity (XXE) attacks and obtain the information stored in the product via unspecified vectors.
network
low complexity
cybozu CWE-611
6.5
2021-10-12 CVE-2021-35496 XXE vulnerability in Tibco Jasperreports Server
The XMLA Connections component of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server, TIBCO JasperReports Server - Community Edition, TIBCO JasperReports Server - Developer Edition, TIBCO JasperReports Server for AWS Marketplace, TIBCO JasperReports Server for ActiveMatrix BPM, and TIBCO JasperReports Server for Microsoft Azure contains a difficult to exploit vulnerability that allows a low privileged attacker with network access to interfere with XML processing in the affected component.
network
high complexity
tibco CWE-611
7.5
2021-10-08 CVE-2021-3312 XXE vulnerability in Alkacon Opencms 11.0/11.0.1/11.0.2
An XML external entity (XXE) vulnerability in Alkacon OpenCms 11.0, 11.0.1 and 11.0.2 allows remote authenticated users with edit privileges to exfiltrate files from the server's file system by uploading a crafted SVG document.
network
low complexity
alkacon CWE-611
6.5
2021-10-07 CVE-2021-38298 XXE vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus before 7110 is vulnerable to blind XXE.
network
low complexity
zohocorp CWE-611
critical
9.8