CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2023-22377
HIGH
tsClinical Define.xml Generator <1.4.0 - XXE
CVSS 7.4
CVE-2023-24187
HIGH
ureport v2.2.9 - XML External Entity Injection via Report File Upload
CVSS 7.8
CVE-2023-22832
HIGH
Apache NiFi 1.2.0-1.19.1 - XML External Entity Injection in ExtractCCDAAttributes Processor
CVSS 7.5
CVE-2023-24323
HIGH
mojoportal v2.7 - Authenticated XML External Entity Injection
CVSS 8.8
CVE-2023-22322
MEDIUM
OMRON CX-Motion Pro <1.4.6.013 - Info Disclosure
CVSS 5.5
CVE-2023-24443
CRITICAL
Jenkins TestComplete support Plugin <2.8.1 - XXE
CVSS 9.8
CVE-2023-24441
CRITICAL
Jenkins MSTest Plugin < 1.0.0 - XML External Entity Injection
CVSS 9.8
CVE-2023-24430
CRITICAL
Jenkins Semantic Versioning Plugin <1.14 - XXE
CVSS 9.8
CVE-2023-24429
CRITICAL
Jenkins Semantic Versioning Plugin <1.14 - SSRF
CVSS 9.8
CVE-2023-21862
HIGH
Oracle Fusion Middleware 12.2.1.4.0 - Unauthenticated RCE
CVSS 8.1
CVE-2023-22624
HIGH
ManageEngine Exchange Reporter Plus < 5708 - XML External Entity Injection
CVSS 7.5
CVE-2023-23595
HIGH
BlueCat Device Registration Portal 2.2 - XML External Entity Injection
CVSS 7.5
CVE-2022-50899
MEDIUM
GeoNetwork 3.10-4.2.0 - XML External Entity Injection via PDF Rendering
CVSS 6.5
CVE-2022-34832
MEDIUM
VERMEG AgileReporter 21.3 - XML External Entity Injection in Analysis Component
CVSS 6.5
CVE-2022-32755
MEDIUM
IBM Security Directory Server 6.4.0 - XML External Entity Injection
CVSS 5.5
CVE-2022-4245
MEDIUM
plexus-utils < 3.0.24 - XML External Entity Injection via Unsanitized Comment Handling
CVSS 4.3
CVE-2022-48565
CRITICAL
Python < 3.6.13 - XML External Entity Injection in plistlib Module
CVSS 9.8
CVE-2022-46751
HIGH
Apache Ivy < 2.5.2 - XML External Entity Injection via DTD Processing
CVSS 8.2
CVE-2022-41221
HIGH
OpenText Archive Center Administration <21.2 - XSS
CVSS 7.1
CVE-2022-45876
MEDIUM
VISAM VBASE < 11.7.5 - XML External Entity Injection
CVSS 5.5
CVE-2022-38840
HIGH
Gralp MAN-EAM-0003 3.2.4 - XML External Entity Injection via XML File Upload
CVSS 7.5
CVE-2022-43941
HIGH
Hitachi Vantara Pentaho Business Analytics Server <9.4.0.1-9.3.0.2 ...
CVSS 7.1
CVE-2022-43473
MEDIUM
ManageEngine OpManager <12.6.168 - SSRF
CVSS 5.8
CVE-2022-36969
HIGH
AVEVA Edge < 2020.2.00.40 - XML External Entity Injection via LoadImportedLibraries Method
CVSS 7.1
CVE-2022-46300
MEDIUM
VISAM VBASE Automation Base <11.7.5 - Info Disclosure
CVSS 5.5
Details
Vulnerabilities
1,250