Vulnerabilities > Mulesoft > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-03-27 CVE-2020-10991 XXE vulnerability in Mulesoft Aplkit
Mulesoft APIkit through 1.3.0 allows XXE because of validation/RestXmlSchemaValidator.java
network
low complexity
mulesoft CWE-611
critical
9.8
2019-12-02 CVE-2019-15631 Unspecified vulnerability in Mulesoft API Gateway and Mule Runtime
Remote Code Execution vulnerability in MuleSoft Mule CE/EE 3.x and API Gateway 2.x released before October 31, 2019 allows remote attackers to execute arbitrary code.
network
low complexity
mulesoft
critical
9.8
2019-10-16 CVE-2019-13116 Deserialization of Untrusted Data vulnerability in Mulesoft Mule Runtime 3.2.0
The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
network
low complexity
mulesoft CWE-502
critical
9.8