CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2021-43142
CRITICAL
jox < 1.16 - XML External Entity Injection via JOXSAXBeanInput readObject
CVSS 9.8
CVE-2021-33208
HIGH
MashZone NextGen <10.7 - XML External Entity
CVSS 7.2
CVE-2021-44477
HIGH
GE ToolBoxST < 07.09.07c - XML External Entity Injection via DTD Parameter Entities
CVSS 7.5
CVE-2021-43090
CRITICAL
predic8 soa_model < 1.6.4 - XML External Entity Injection in WSDLParser
CVSS 9.8
CVE-2021-42194
HIGH
EyouCMS 1.5.4-UTF8-SP3 - XXE via wechat_return XML Parsing
CVSS 7.2
CVE-2021-46365
HIGH
Magnolia CMS < 6.2.4 - XML External Entity Injection via XLF File
CVSS 7.8
CVE-2021-46660
CRITICAL
Signiant Manager+Agents <15.1 - XSS
CVSS 9.8
CVE-2021-40722
CRITICAL
AEM Forms Cloud Service <6.5.10.0 - XXE Injection
CVSS 9.8
CVE-2021-42560
HIGH
MITRE Caldera 2.9.0 - XML External Entity Injection via Debrief Plugin SVG Parameter
CVSS 8.8
CVE-2021-44028
MEDIUM
Quest KACE Desktop Authority 10.0-11.1 - XML External Entity Injection via log4net Configuration
CVSS 5.5
CVE-2021-45096
MEDIUM
KNIME Analytics Platform < 4.5.0 - XML External Entity Injection via Crafted Workflow File
CVSS 4.7
CVE-2021-3836
MEDIUM
DBeaver <=21.2.3 - XML External Entity Injection
CVSS 5.5
CVE-2021-23463
HIGH
H2 < 2.0.202 - XXE
CVSS 8.1
CVE-2021-44557
CRITICAL
multiNER < 08-25-2021 - XML External Entity Injection in ner.py
CVSS 9.1
CVE-2021-44556
CRITICAL
kb/digger < 08-25-2021 - XML External Entity Injection
CVSS 9.1
CVE-2021-42776
HIGH
CloverDX Server < 5.11.2 and 5.12.x < 5.12.1 - XML External Entity Injection via Configuration Import
CVSS 7.7
CVE-2021-44147
MEDIUM
Claris FileMaker Pro and Server < 19.4.1 - XML External Entity Injection via Crafted XML/Excel Document
CVSS 5.5
CVE-2021-43577
HIGH
Jenkins OWASP Dependency-Check Plugin <5.1.1 - XXE
CVSS 7.1
CVE-2021-43576
MEDIUM
Jenkins pom2config Plugin <1.2 - XXE
CVSS 6.5
CVE-2021-21701
MEDIUM
Jenkins Performance Plugin < 3.20 - XML External Entity Injection
CVSS 6.5
CVE-2021-36172
MEDIUM
FortiPortal <6.0.6 - DoS/Info Disclosure
CVSS 4.3
CVE-2021-20839
MEDIUM
Office Server Document Converter <7.2MR4, <7.1MR7 - DoS
CVSS 6.5
CVE-2021-20838
HIGH
Office Server Document Converter <7.2MR4, <7.1MR7 - DoS
CVSS 7.5
CVE-2021-3869
HIGH
Stanford CoreNLP <=4.3.1 - XML External Entity Injection
CVSS 7.5
CVE-2021-3878
CRITICAL
Stanford CoreNLP <=4.3.1 - XML External Entity Injection
CVSS 9.8
Details
Vulnerabilities
1,250