Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-07-15 | CVE-2019-17637 | XXE vulnerability in multiple products In all versions of Eclipse Web Tools Platform through release 3.18 (2020-06), XML and DTD files referring to external entities could be exploited to send the contents of local files to a remote server when edited or validated, even when external entity resolution is disabled in the user preferences. | 7.1 |
2020-07-14 | CVE-2020-4510 | XXE vulnerability in IBM Qradar Security Information and Event Manager IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. | 5.5 |
2020-07-14 | CVE-2020-12025 | XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02 Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program. | 3.3 |
2020-06-30 | CVE-2020-5602 | XXE vulnerability in Mitsubishielectric products Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver. | 7.5 |
2020-06-23 | CVE-2020-14940 | XXE vulnerability in Herac Tuxguitar 1.5.4 An issue was discovered in io/gpx/GPXDocumentReader.java in TuxGuitar 1.5.4. | 7.5 |
2020-06-22 | CVE-2020-14204 | XXE vulnerability in IBI Webfocus Business Intelligence 8.0 In WebFOCUS Business Intelligence 8.0 (SP6), the administration portal allows remote attackers to read arbitrary local files or forge server-side HTTP requests via a crafted HTTP request to /ibi_apps/WFServlet.cfg because XML external entity injection is possible. | 8.2 |
2020-06-16 | CVE-2020-8541 | XXE vulnerability in Open-Xchange Appsuite 7.10.1/7.10.2/7.10.3 OX App Suite through 7.10.3 allows XXE attacks. | 6.5 |
2020-06-06 | CVE-2020-13883 | XXE vulnerability in Wso2 products In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle. | 6.7 |
2020-06-04 | CVE-2020-13692 | XXE vulnerability in multiple products PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. | 7.7 |
2020-06-04 | CVE-2020-4509 | XXE vulnerability in IBM Qradar Security Information and Event Manager 7.3.0/7.4.0 IBM QRadar SIEM 7.3 and 7.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. | 7.6 |