Show filters
108 Total Results
Displaying 1-10 of 108
Sort by:
Attacker Value
Moderate
CVE-2020-10799
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
0
Attacker Value
Unknown
CVE-2020-28734
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
0
Attacker Value
Unknown
CVE-2020-26247
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.
0
Attacker Value
Unknown
CVE-2020-28736
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
0
Attacker Value
Unknown
CVE-2020-35604
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
0
Attacker Value
Unknown
CVE-2020-35123
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
0
Attacker Value
Unknown
CVE-2020-29436
Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
0
Attacker Value
Unknown
CVE-2020-26513
Disclosure Date: December 07, 2020 (last updated February 22, 2025)
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
0
Attacker Value
Unknown
CVE-2020-25649
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
0
Attacker Value
Unknown
CVE-2020-2324
Disclosure Date: December 03, 2020 (last updated February 22, 2025)
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0