CWE-611

Improper Restriction of XML External Entity Reference

Parent: CWE-610 - Externally Controlled Reference to a Resource in Another Sphere

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

1,228 vulnerabilities with CWE-611
CVE-2024-22024 HIGH
Ivanti Connect Secure - XXE
CVSS 8.3
CVE-2024-24743 HIGH
SAP Netweaver Application Server Java - XXE
CVSS 8.6
CVE-2024-1167 MEDIUM
SEW-EURODRIVE MOVITOOLS MotionStudio - Info Disclosure
CVSS 5.5
CVE-2024-22380 MEDIUM
Electronic Delivery Check System - XXE
CVSS 5.5
CVE-2024-21796 MEDIUM
Dfeg Electronic Deliverables Creation Support Tool < 1.0.4 - XXE
CVSS 5.5
CVE-2024-21765 MEDIUM
Cals-ed Electronic Delivery Check System < 11.0.0 - XXE
CVSS 5.5
CVE-2024-23525 MEDIUM
Tozt Spreadsheet < 0.30 - XXE
CVSS 6.5
CVE-2023-7307 HIGH
Sangfor Behavior Management System - XXE Injection
CVE-2023-38693 CRITICAL
Lucee <5.4.3.2-5.3.9.173 - RCE
CVSS 9.8
CVE-2023-47160 HIGH
IBM Cognos Controller < 11.0.1.4 - XXE
CVSS 8.2
CVE-2023-24466 HIGH
OpenText iManager <3.2.6.0200 - XSS
CVSS 7.5
CVE-2023-37233 HIGH
Loftware Spectrum < 4.6_hf14 - XXE
CVSS 8.8
CVE-2023-48362 HIGH
Apache Drill < 1.21.2 - XXE
CVSS 8.8
CVE-2023-50304 HIGH
IBM Engineering Requirements Management Doors - XXE
CVSS 7.1
CVE-2023-49110 HIGH
Kiuwan - XML External Entity Injection
CVSS 7.2
CVE-2023-45192 HIGH
IBM Doors Next - XXE
CVSS 8.2
CVE-2023-51605 MEDIUM
Honeywell Saia PG5 Controls Suite - Info Disclosure
CVSS 6.5
CVE-2023-51604 MEDIUM
Honeywell Saia PG5 Controls Suite - Info Disclosure
CVSS 6.5
CVE-2023-51602 MEDIUM
Honeywell Saia PG5 Controls Suite - Info Disclosure
CVSS 6.5
CVE-2023-51601 MEDIUM
Honeywell Saia PG5 Controls Suite - Info Disclosure
CVSS 6.5
CVE-2023-51600 MEDIUM
Honeywell Saia PG5 Controls Suite - Info Disclosure
CVSS 6.5
CVE-2023-51591 HIGH
Voltronic Power ViewPower Pro - Info Disclosure
CVSS 7.5
CVE-2023-44412 HIGH
Dlink D-view 8 - XXE
CVSS 8.2
CVE-2023-42035 MEDIUM
Visualware Myconnection Server - XXE
CVSS 6.5
CVE-2023-40507 HIGH
LG Simple Editor - Info Disclosure
CVSS 7.5
Details
Vulnerabilities 1,228