Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2021-22501

Published Dec 19, 2024

Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input Data Manipulation.  The vulnerability could be exploited t…

CVSS 5.3 · Medium

CVE-2024-55887

Published Dec 13, 2024

Ucum-java is a FHIR Java library providing UCUM Services. In versions prior to 1.0.9, XML parsing performed by the UcumEssenceService is vulnerable to XML external entity injectio…

CVSS 8.6 · High

CVE-2024-55875

Published Dec 12, 2024

http4k is a functional toolkit for Kotlin HTTP applications. Prior to version 6.50.0.0, there is a potential XXE (XML External Entity Injection) vulnerability when http4k handling…

CVSS 9.8 · Critical

CVE-2024-54005

Published Dec 10, 2024

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V1…

CVSS 5.9 · Medium

CVE-2024-49704

Published Dec 10, 2024

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10.4.1 (All versions), COMOS V10.4.2 (All versions), COMOS V1…

CVSS 5.7 · Medium

CVE-2024-47582

Published Dec 10, 2024

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which leads to XML Entity Expansion attack. This causes limited impac…

CVSS 5.3 · Medium

CVE-2024-46455

Published Dec 9, 2024

unstructured v.0.14.2 and before is vulnerable to XML External Entity (XXE) via the XMLParser.

CVSS 9.8 · Critical

CVE-2024-52806

Published Dec 2, 2024

SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XX…

CVSS 8.3 · High

CVE-2024-52596

Published Dec 2, 2024

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for example the SAMLResponse, it's possible to induce an XXE. T…

CVSS 8.8 · High

CVE-2024-52800

Published Nov 29, 2024

veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI invokes an XSL transformation that may theoretically lead to…

CVSS 2.3 · Low

CVE-2024-9044

Published Nov 29, 2024

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS.

CVSS 4.6 · Medium

CVE-2024-53675

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-53674

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11622

Published Nov 26, 2024

An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain cases.

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-24466

Published Nov 22, 2024

Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50848

Published Nov 18, 2024

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute ar…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-48917

Published Nov 18, 2024

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method which should prevent XXE attacks. However, in a bypass of the p…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-47873

Published Nov 18, 2024

PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which should prevent XXE attacks. However, prior to versions 1.9.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-26066

Published Nov 18, 2024

A vulnerability in the web UI of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-1483

Published Nov 15, 2024

A vulnerability in the web UI of Cisco&nbsp;SD-WAN vManage Software could allow an authenticated, remote attacker to gain read and write access to information that is stored on an…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-3902

Published Nov 15, 2024

An improper restriction of external entities (XXE) vulnerability in dompdf/dompdf's SVG parser allows for Server-Side Request Forgery (SSRF) and deserialization attacks. This issu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-5919

Published Nov 14, 2024

A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authenticated attacker to exfiltrate arbitrary files from firewall…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 201-225 of 1,270 CVEsPage 9 of 51