CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,253 vulnerabilities with CWE-611
CVE-2018-11586
CRITICAL
SearchBlox 8.6.7 - Unauthenticated XML External Entity Injection via REST API Status Endpoint
CVSS 9.8
CVE-2018-1000198
MEDIUM
Jenkins Black Duck Hub Plugin <3.1.0 - SSRF
CVSS 6.5
CVE-2018-10613
HIGH
GE MDS PulseNET and MDS PulseNET Enterprise <= 3.2.1 - XML External Entity Injection
CVSS 7.5
CVE-2018-10653
CRITICAL
Citrix XenMobile Server <10.8 - XSS
CVSS 9.8
CVE-2018-1309
CRITICAL
Apache NiFi < 1.6.0 - XML External Entity Injection in SplitXML Processor
CVSS 9.8
CVE-2018-8010
MEDIUM
Apache Solr 6.0.0-6.6.3 and 7.0.0-7.3.0 - XML External Entity Injection in Config Files
CVSS 5.5
CVE-2018-4942
HIGH
Adobe ColdFusion - XML External Entity Injection
CVSS 7.5
CVE-2018-10832
MEDIUM
ModbusPal 1.6b - XML External Entity Injection via Crafted .xmpp or .xmpa Files
CVSS 5.5
CVE-2018-1259
HIGH
Spring Data Commons 1.13-1.13.11 & 2.0-2.0.6 - XXE via Projection-Based Request Binding
CVSS 7.5
CVE-2018-0765
HIGH
.NET and .NET Core - Denial of Service via XML Document Processing
CVSS 7.5
CVE-2018-1247
HIGH
RSA Authentication Manager < 8.3 - XML External Entity Injection via Malicious DTD
CVSS 7.1
CVE-2018-1183
CRITICAL
Dell EMC <8.4.0.8 - Info Disclosure
CVSS 9.8
CVE-2018-10175
MEDIUM
Digital Guardian Management Console <7.1.2.0015 - SSRF
CVSS 6.5
CVE-2018-10077
MEDIUM
Geist WatchDog Console 3.2.2 - Info Disclosure
CVSS 4.9
CVE-2018-1308
HIGH
Apache Solr 1.2-6.6.2 and 7.0.0-7.2.1 - XML External Entity Injection via DataImportHandler Inline XML Parameter
CVSS 7.5
CVE-2018-1421
HIGH
IBM WebSphere DataPower Appliances <7.6 - XXE
CVSS 7.1
CVE-2018-9116
CRITICAL
WireMock < 2.16.0 - Unauthenticated XML External Entity Injection
CVSS 9.1
CVE-2018-6225
MEDIUM
Trend Micro Email Encryption Gateway 5.5 - Authenticated XML External Entity Injection
CVSS 4.3
CVE-2018-2401
MEDIUM
SAP Business Process Automation By Redwood - XML External Entity Injection
CVSS 5.4
CVE-2018-1077
HIGH
Spacewalk 2.6 - XML External Entity Injection via API
CVSS 7.5
CVE-2018-0878
LOW
Windows Remote Assistance - Information Disclosure via XML External Entity Processing
CVSS 3.1
CVE-2018-1000124
CRITICAL
I Librarian I-librarian <4.8 - XML External Entity (XXE) SSRF
CVSS 10.0
CVE-2018-1000090
HIGH
textpattern 4.6.2 - Denial of Service via XML External Entity Injection in Import XML Feature
CVSS 7.5
CVE-2018-1000069
MEDIUM
FreePlane < 1.5.9 - XML External Entity Injection in Mindmap Loader
CVSS 5.5
CVE-2018-5758
MEDIUM
Aurea Jive-n 9.0.2.1 - XML External Entity Injection via Upload File Functionality
CVSS 6.5
Details
Vulnerabilities
1,253