Skip to main content

CWE archive

CWE-611 CVEs

Programmatic archive

1,270 CVEs tagged with CWE-611259 Critical, 567 High, 410 Medium, 34 Low, 0 Unrated.

CVE-2025-26400

Published Jul 29, 2025

SolarWinds Web Help Desk was reported to be affected by an XML External Entity Injection (XXE) vulnerability that could lead to information disclosure. A valid, low-privilege acce…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54445

Published Jul 23, 2025

Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Server Side Request Forgery.This issue affects MagicINFO 9 Ser…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7766

Published Jul 22, 2025

Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on…

CVSS 8.6 · High

CVE-2025-34142

Published Jul 22, 2025

An XML External Entity (XXE) injection vulnerability exists in ETQ Reliance on the CG (legacy) platform within the `/resources/sessions/sso` endpoint. The SAML authentication hand…

CVSS 6.9 · Medium

CVE-2025-36603

Published Jul 21, 2025

Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially ex…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7824

Published Jul 19, 2025

A vulnerability was found in Jinher OA 1.1. It has been rated as problematic. This issue affects some unknown processing of the file XmlHttp.aspx. The manipulation leads to xml ex…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7823

Published Jul 19, 2025

A vulnerability was found in Jinher OA 1.2. It has been declared as problematic. This vulnerability affects unknown code of the file ProjectScheduleDelete.aspx. The manipulation l…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-52162

Published Jul 18, 2025

agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the RSSReader endpoint. This vulnerability allows attackers to…

CVSS 6.5 · Medium

CVE-2025-53621

Published Jul 15, 2025

DSpace open source software is a repository application which provides durable access to digital resources. Two related XML External Entity (XXE) injection possibilities impact al…

CVSS 6.9 · Medium

CVE-2025-53689

Published Jul 14, 2025

Blind XXE Vulnerabilities in jackrabbit-spi-commons and jackrabbit-core in Apache Jackrabbit < 2.23.2 due to usage of an unsecured document build to load privileges. Users are re…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-7523

Published Jul 13, 2025

A vulnerability was found in Jinher OA 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /c6/Jhsoft.Web.message/ToolBar/DelTemp.a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6438

Published Jul 11, 2025

A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause manipulation of SOAP API calls and XML external entities injection re…

CVSS 5.9 · Medium

CVE-2025-49544

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Secu…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49539

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a secu…

CVSS 4.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-49535

Published Jul 8, 2025

ColdFusion versions 2025.2, 2023.14, 2021.20 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could result in a Secu…

CVSS 9.3 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49493

Published Jun 30, 2025

Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.

CVSS 5.8 · Medium

CVE-2025-52888

Published Jun 24, 2025

Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. A critical XML External Entity (XXE) vulnerability exists in the xunit-xml-plugin used b…

CVSS 7.5 · High

CVE-2025-47293

Published Jun 19, 2025

PowSyBl (Power System Blocks) is a framework to build power system oriented software. Prior to version 6.7.2, in certain places, powsybl-core XML parsing is vulnerable to an XML e…

CVSS 2.7 · Low

CVE-2025-44044

Published Jun 10, 2025

Keyoti SearchUnit prior to 9.0.0. is vulnerable to XML External Entity (XXE). An attacker who can force a vulnerable SearchUnit host into parsing maliciously crafted XML and/or DT…

CVSS 7.5 · High

CVE-2024-34711

Published Jun 10, 2025

GeoServer is an open source server that allows users to share and edit geospatial data. An improper URI validation vulnerability exists that enables an unauthorized attacker to pe…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31039

Published Jun 9, 2025

Improper Restriction of XML External Entity Reference vulnerability in pixelgrade Category Icon category-icon allows XML Entity Linking.This issue affects Category Icon: from n/a…

CVSS 9.1 · Critical

CVE-2025-5877

Published Jun 9, 2025

A vulnerability, which was classified as problematic, has been found in Fengoffice Feng Office 3.2.2.1. Affected by this issue is some unknown functionality of the file /applicati…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 126-150 of 1,270 CVEsPage 6 of 51