Show filters
108 Total Results
Displaying 1-10 of 108
Sort by:
Attacker Value
Moderate

CVE-2020-10799

Disclosure Date: March 20, 2020 (last updated February 21, 2025)
The svglib package through 0.9.3 for Python allows XXE attacks via an svg2rlg call.
Attacker Value
Unknown

CVE-2020-28734

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Plone before 5.2.3 allows XXE attacks via a feature that is explicitly only available to the Manager role.
Attacker Value
Unknown

CVE-2020-26247

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Nokogiri is a Rubygem providing HTML, XML, SAX, and Reader parsers with XPath and CSS selector support. In Nokogiri before version 1.11.0.rc4 there is an XXE vulnerability. XML Schemas parsed by Nokogiri::XML::Schema are trusted by default, allowing external resources to be accessed over the network, potentially enabling XXE or SSRF attacks. This behavior is counter to the security policy followed by Nokogiri maintainers, which is to treat all input as untrusted by default whenever possible. This is fixed in Nokogiri version 1.11.0.rc4.
Attacker Value
Unknown

CVE-2020-28736

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Plone before 5.2.3 allows XXE attacks via a feature that is protected by an unapplied permission of plone.schemaeditor.ManageSchemata (therefore, only available to the Manager role).
Attacker Value
Unknown

CVE-2020-35604

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
An XXE attack can occur in Kronos WebTA 5.0.4 when SAML is used.
Attacker Value
Unknown

CVE-2020-35123

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
In Zimbra Collaboration Suite Network Edition versions < 9.0.0 P10 and 8.8.15 P17, there exists an XXE vulnerability in the saml consumer store extension, which is vulnerable to XXE attacks. This has been fixed in Zimbra Collaboration Suite Network edition 9.0.0 Patch 10 and 8.8.15 Patch 17.
Attacker Value
Unknown

CVE-2020-29436

Disclosure Date: December 17, 2020 (last updated February 22, 2025)
Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.
Attacker Value
Unknown

CVE-2020-26513

Disclosure Date: December 07, 2020 (last updated February 22, 2025)
An issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The ReqIF XML data, used by the codebeamer ALM application to import projects, is parsed by insecurely configured software components, which can be abused for XML External Entity Attacks.
Attacker Value
Unknown

CVE-2020-25649

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.
Attacker Value
Unknown

CVE-2020-2324

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.