CWE-611
Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
1,253 vulnerabilities with CWE-611
CVE-2018-7230
HIGH
Schneider Electric Pelco Sarix Professional < 3.29.67 - XML External Entity Injection via Web Interface Import
CVSS 8.8
CVE-2018-0218
LOW
Cisco Secure Access Control Server - XML External Entity Injection via Imported XML File
CVSS 3.3
CVE-2018-0207
LOW
Cisco Secure Access Control Server - XML External Entity Injection via Crafted XML File Import
CVSS 3.3
CVE-2018-6489
CRITICAL
Micro Focus Project and Portfolio Management Center 9.32 - XML External Entity Injection
CVSS 9.8
CVE-2018-2393
HIGH
SAP Internet Graphics Server 7.20, 7.20EXT, 7.45, 7.49, 7.53 - XML External Entity Injection
CVSS 7.5
CVE-2018-2392
HIGH
SAP Internet Graphics Server (IGS) XMLCHART XXE
CVSS 7.5
CVE-2018-1000056
HIGH
Jenkins JUnit Plugin <1.23 - SSRF/DoS
CVSS 8.3
CVE-2018-1000055
HIGH
Jenkins Android Lint Plugin <2.5 - SSRF/DoS
CVSS 8.3
CVE-2018-1000054
HIGH
Jenkins CCM Plugin < 3.1 - XML External Entity Injection in Build Process
CVSS 8.3
CVE-2018-3600
MEDIUM
Trend Micro Control Manager 6.0 - Info Disclosure
CVSS 6.5
CVE-2018-1307
HIGH
Apache jUDDI 3.2-3.3.4 - XML External Entity Injection via WADL2Java or WSDL2Java
CVSS 8.1
CVE-2018-5789
HIGH
Extreme Networks ExtremeWireless <5.8.6.9-5.9.1.3 - DoS
CVSS 7.5
CVE-2018-6486
HIGH
Micro Focus Fortify Audit Workbench and Software Security Center 16.10, 16.20, 17.10 - XML External Entity Injection
CVSS 7.3
CVE-2018-1364
HIGH
IBM Content Navigator 2.0 and 3.0 - XML External Entity Injection
CVSS 8.2
CVE-2018-1000012
HIGH
Jenkins Warnings Plugin < 4.64 - XML External Entity Injection
CVSS 8.8
CVE-2018-1000011
HIGH
Jenkins FindBugs Plugin < 4.71 - XML External Entity Injection in Build Process
CVSS 8.8
CVE-2018-1000010
HIGH
Jenkins DRY Plugin < 2.49 - Authenticated XML External Entity Injection
CVSS 8.8
CVE-2018-1000009
HIGH
Jenkins Checkstyle Plugin < 3.49 - XML External Entity Injection
CVSS 8.8
CVE-2018-1000008
HIGH
Jenkins PMD Plugin < 3.49 - XML External Entity Injection
CVSS 8.8
CVE-2018-0108
MEDIUM
Cisco WebEx Meetings Server - XML External Entity Injection
CVSS 5.3
CVE-2018-0100
MEDIUM
Cisco AnyConnect Secure Mobility Client - XML External Entity Injection via Profile Editor
CVSS 4.4
CVE-2017-20151
MEDIUM
iText RUPS - XML External Entity Reference
CVSS 5.5
CVE-2017-15725
HIGH
Dzone AnswerHub - XML External Entity Injection
CVSS 7.5
CVE-2017-18438
MEDIUM
cPanel 55.9999.61-64.0.20 - Authenticated Remote Code Execution via Encoding API
CVSS 6.3
CVE-2017-18111
HIGH
Atlassian Application Links <5.0.10, 5.1.0-5.1.3, 5.2.0-5.2.6 - XML External Entity Injection via OAuthHelper
CVSS 8.7
Details
Vulnerabilities
1,253