Vulnerabilities > Improper Restriction of XML External Entity Reference ('XXE')

DATE CVE VULNERABILITY TITLE RISK
2019-10-23 CVE-2019-14276 XXE vulnerability in Xnat 1.7.5.3
WUSTL XNAT 1.7.5.3 allows XXE attacks via a POST request body.
network
low complexity
xnat CWE-611
6.5
2019-10-10 CVE-2019-1060 XXE vulnerability in Microsoft products
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka 'MS XML Remote Code Execution Vulnerability'.
network
microsoft CWE-611
critical
9.3
2019-10-02 CVE-2019-12711 XXE vulnerability in Cisco Unified Communications Manager
A vulnerability in the web-based interface of Cisco Unified Communications Manager and Cisco Unified Communications Manager Session Management Edition (SME) could allow an unauthenticated, remote attacker to access sensitive information or cause a denial of service (DoS) condition.
network
low complexity
cisco CWE-611
6.4
2019-09-25 CVE-2019-16188 XXE vulnerability in Hcltech Appscan Source
HCL AppScan Source before 9.03.13 is susceptible to XML External Entity (XXE) attacks in multiple locations.
network
hcltech CWE-611
5.8
2019-09-11 CVE-2019-9488 XXE vulnerability in Trendmicro Deep Security Manager and vulnerability Protection
Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack.
network
low complexity
trendmicro CWE-611
4.0
2019-09-09 CVE-2019-16174 XXE vulnerability in Limesurvey
An XML injection vulnerability was found in Limesurvey before 3.17.14 that allows remote attackers to import specially crafted XML files and execute code or compromise data integrity.
6.8
2019-09-03 CVE-2019-6179 XXE vulnerability in Lenovo Xclarity Administrator and Xclarity Integrator
An XML External Entity (XXE) processing vulnerability was reported in Lenovo XClarity Administrator (LXCA) prior to version 2.5.0 , Lenovo XClarity Integrator (LXCI) for Microsoft System Center prior to version 7.7.0, and Lenovo XClarity Integrator (LXCI) for VMWare vCenter prior to version 6.1.0 that could allow information disclosure.
network
low complexity
lenovo CWE-611
7.5
2019-08-29 CVE-2019-13608 XXE vulnerability in Citrix Storefront Server
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
network
low complexity
citrix CWE-611
5.0
2019-08-26 CVE-2019-15641 XXE vulnerability in Webmin
xmlrpc.cgi in Webmin through 1.930 allows authenticated XXE attacks.
network
low complexity
webmin CWE-611
6.8
2019-08-26 CVE-2019-15637 XXE vulnerability in Tableau products
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS.
network
low complexity
tableau CWE-611
5.5