CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,252 vulnerabilities with CWE-611
CVE-2021-29140
HIGH
Aruba ClearPass 6.7.0-6.7.13 - XML External Entity Injection
CVSS 8.2
CVE-2021-25163
HIGH
Aruba AirWave < 8.2.12.1 - XML External Entity Injection
CVSS 8.1
CVE-2021-25165
HIGH
Aruba AirWave < 8.2.12.1 - XML External Entity Injection
CVSS 8.1
CVE-2021-25164
MEDIUM
Aruba AirWave < 8.2.12.1 - XML External Entity Injection
CVSS 6.5
CVE-2021-27736
MEDIUM
FusionAuth fusionauth-samlv2 <0.5.4 - XML External Entity
CVSS 6.5
CVE-2021-21642
HIGH
Jenkins Config File Provider Plugin < 3.7.0 - XML External Entity Injection
CVSS 8.1
CVE-2021-20454
HIGH
IBM WebSphere Application Server <9.0 - XXE
CVSS 8.2
CVE-2021-20453
HIGH
IBM WebSphere Application Server <9.0 - XXE
CVSS 8.2
CVE-2021-29447
HIGH
WordPress 5.6.0-5.7.0 - Authenticated XML External Entity Injection via Media Library File Upload
CVSS 7.1
CVE-2021-27604
MEDIUM
SAP NetWeaver ABAP Server/ABAP Platform <7.50 - XSS
CVSS 6.5
CVE-2021-28973
MEDIUM
Perforce Helix ALM 2020.3.1 Build 22 - XML External Entity Injection via XML Import
CVSS 4.9
CVE-2021-22158
HIGH
Proofpoint Insider Threat Management < 7.9.3 - Authenticated XML External Entity Injection
CVSS 7.2
CVE-2021-29421
HIGH
pikepdf 1.3.0-2.9.2 - XML External Entity Injection in XMP Metadata Parser
CVSS 7.5
CVE-2021-20502
HIGH
IBM Jazz Foundation Products - XML External Entity Injection
CVSS 7.1
CVE-2021-20482
HIGH
IBM Cloud Pak for Automation <20.0.2,20.0.3 - XXE
CVSS 7.1
CVE-2021-1628
CRITICAL
Mule 4.0.0-4.2.1 - XML External Entity Injection
CVSS 9.8
CVE-2021-28110
HIGH
TranzWare e-Commerce Payment Gateway <3.1.27.5 - XML Injection
CVSS 7.5
CVE-2021-26969
MEDIUM
Aruba AirWave < 8.2.12.0 - Authenticated XML External Entity Injection
CVSS 6.5
CVE-2021-27931
CRITICAL
LumisXP <10.0.0 - Blind XML External Entity Attack
CVSS 9.1
CVE-2021-26703
CRITICAL
EPrints 3.4.2 - XML External Entity File Read via JSON/XML Input
CVSS 9.8
CVE-2021-21517
HIGH
Dell EMC SRS Policy Manager 6.X - Unauthenticated XML External Entity Injection via DTD Processing
CVSS 7.2
CVE-2021-27184
HIGH
Pelco Digital Sentry Server 7.18.72.11464 - XML External Entity Injection via ControlPointCacheShare.xml
CVSS 7.5
CVE-2021-20353
HIGH
IBM WebSphere Application Server <9.0 - XXE
CVSS 8.2
CVE-2021-21266
MEDIUM
openHAB < 2.5.12 - XML External Entity Injection via SSDP Response Parsing
CVSS 6.4
CVE-2021-23901
CRITICAL
Apache Nutch < 1.18 - XML External Entity Injection in DmozParser
CVSS 9.1
Details
Vulnerabilities
1,252