Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2021-06-29 CVE-2021-22338 XXE vulnerability in Huawei Ecns280 Firmware V100R005C00/V100R005C10
There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10.
network
low complexity
huawei CWE-611
5.3
2021-06-23 CVE-2021-29620 XXE vulnerability in Reportportal Service-Api
Report portal is an open source reporting and analysis framework.
network
low complexity
reportportal CWE-611
7.5
2021-06-21 CVE-2021-35066 XXE vulnerability in Connectwise Automate
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
network
low complexity
connectwise CWE-611
critical
9.8
2021-06-21 CVE-2021-28684 XXE vulnerability in Powerarchiver
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
network
low complexity
powerarchiver CWE-611
4.3
2021-06-16 CVE-2021-33813 XXE vulnerability in multiple products
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
network
low complexity
jdom apache debian fedoraproject oracle CWE-611
7.5
2021-06-11 CVE-2020-5003 XXE vulnerability in IBM Financial Transaction Manager 3.2.4
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm CWE-611
critical
9.1
2021-06-09 CVE-2021-27635 XXE vulnerability in SAP Netweaver Application Server for Java
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash.
network
low complexity
sap CWE-611
6.5
2021-06-08 CVE-2020-25817 XXE vulnerability in Silverstripe
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser.
network
low complexity
silverstripe CWE-611
4.8
2021-06-01 CVE-2019-4730 XXE vulnerability in multiple products
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm netapp CWE-611
7.1
2021-06-01 CVE-2020-4300 XXE vulnerability in multiple products
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data.
network
low complexity
ibm netapp CWE-611
8.2