CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,250 vulnerabilities with CWE-611
CVE-2021-23418
MEDIUM
glances < 3.2.1 - XML External Entity Injection via Fault XML Parser
CVSS 6.3
CVE-2021-20399
CRITICAL
IBM QRadar SIEM 7.3-7.4.3 GA - XML External Entity Information Disclosure
CVSS 9.1
CVE-2021-22523
HIGH
Micro Focus Verastream Host Integrator <7.8.1 - SSRF
CVSS 7.6
CVE-2021-2401
MEDIUM
Oracle BI Publisher <12.2.1.4.0 - Info Disclosure
CVSS 5.3
CVE-2021-20595
HIGH
Mitsubishi Electric Air Conditioning Systems - XML External Entity Injection
CVSS 8.2
CVE-2021-32754
MEDIUM
FlowDroid < 2.9.0 - XML External Entity Injection via Source/Sink Definition File
CVSS 5.3
CVE-2021-30201
HIGH
Kaseya VSA < 9.5.6 - XML External Entity Injection via KaseyaWS.asmx API
CVSS 7.5
CVE-2021-32972
MEDIUM
Panasonic FPWIN Pro <7.5.1.1 - Info Disclosure
CVSS 5.5
CVE-2021-21672
MEDIUM
Jenkins Selenium HTML Report Plugin <= 1.0 - XML External Entity Injection
CVSS 4.3
CVE-2021-25951
HIGH
XML2Dict 0.2.2 - XML External Entity Denial of Service
CVSS 7.5
CVE-2021-22338
MEDIUM
Huawei eCNS280 V100R005C00 and V100R005C10 - XML External Entity Injection
CVSS 5.3
CVE-2021-29620
HIGH
ReportPortal service-api 3.1.0-5.3.9 - XML External Entity Injection via Imported XML File
CVSS 7.5
CVE-2021-35066
CRITICAL
ConnectWise Automate <2021.0.6.132 - XSS
CVSS 9.8
CVE-2021-28684
MEDIUM
PowerArchiver < 20.10.02 - XML External Entity Injection
CVSS 4.3
CVE-2021-33813
HIGH
JDOM < 2.0.6 - XML External Entity Injection via SAXBuilder
CVSS 7.5
CVE-2021-27635
MEDIUM
SAP NetWeaver AS for JAVA - Info Disclosure
CVSS 6.5
CVE-2021-27492
MEDIUM
KeyShot <v10.1 - Info Disclosure
CVSS 5.5
CVE-2021-20492
HIGH
IBM WebSphere Application Server <9.0 - XXE
CVSS 8.2
CVE-2021-32925
MEDIUM
Chamilo 1.11.0-1.11.15 - Authenticated XML External Entity Injection in User Import
CVSS 6.5
CVE-2021-22140
HIGH
Elastic App Search 7.11.0-7.11.9 - XML External Entity Injection via Web Crawler Sitemap Processing
CVSS 7.5
CVE-2021-30006
HIGH
IntelliJ IDEA <2020.3.3 - Info Disclosure
CVSS 7.5
CVE-2021-1530
MEDIUM
Cisco BroadWorks Messaging Server - XML External Entity Injection via XML File Upload
CVSS 5.4
CVE-2021-1369
MEDIUM
Cisco Firepower Device Manager < 6.5.0.5 - Authenticated XML External Entity Injection via REST API
CVSS 5.4
CVE-2021-29140
HIGH
Aruba ClearPass 6.7.0-6.7.13 - XML External Entity Injection
CVSS 8.2
CVE-2021-25163
HIGH
Aruba AirWave < 8.2.12.1 - XML External Entity Injection
CVSS 8.1
Details
Vulnerabilities
1,250