Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,283 CVEs tagged with CWE-611260 Critical, 574 High, 415 Medium, 34 Low, 0 Unrated.

CVE-2024-9044

Published Nov 29, 2024

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

CVSS 4.6 · Medium

CVE-2024-53675

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53674

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11622

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24466

Published Nov 22, 2024

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50848

Published Nov 18, 2024

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48917

Published Nov 18, 2024

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks. However, in a bypass of the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47873

Published Nov 18, 2024

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. However, prior to versions 1.9.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26066

Published Nov 18, 2024

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1483

Published Nov 15, 2024

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3902

Published Nov 15, 2024

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5919

Published Nov 14, 2024

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewall…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10218

Published Nov 12, 2024

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO Hawk and TIBCO Operational Intelligence

CVSS 9.2 · Critical

CVE-2024-52007

Published Nov 8, 2024

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML externa…

CVSS 8.6 · High

CVE-2024-20531

Published Nov 6, 2024

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device and conduct…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51132

Published Nov 5, 2024

An XML External Entity (XXE) vulnerability in HAPI FHIR before v6.4.0 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted request co…

CVSS 9.8 · Critical

CVE-2024-45086

Published Nov 4, 2024

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this vulnerab…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-51136

Published Nov 4, 2024

An XML External Entity (XXE) vulnerability in Dmoz2CSV in openimaj v1.3.10 allows attackers to access sensitive information or execute arbitrary code via supplying a crafted XML f…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-4690

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4189

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-4184

Published Oct 16, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD Injection.This issue affects OpenText Application Automatio…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,283 CVEsPage 10 of 52