Show filters
190 Total Results
Displaying 21-30 of 190
Sort by:
Attacker Value
Unknown
CVE-2021-21672
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
Jenkins Selenium HTML report Plugin 1.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
0
Attacker Value
Unknown
CVE-2021-25951
Disclosure Date: June 30, 2021 (last updated February 22, 2025)
XXE vulnerability in 'XML2Dict' version 0.2.2 allows an attacker to cause a denial of service.
0
Attacker Value
Unknown
CVE-2021-22338
Disclosure Date: June 29, 2021 (last updated February 22, 2025)
There is an XXE injection vulnerability in eCNS280 V100R005C00 and V100R005C10. A module does not perform the strict operation to the input XML message. Attacker can send specific message to exploit this vulnerability, leading to the module denial of service.
0
Attacker Value
Unknown
CVE-2021-29620
Disclosure Date: June 23, 2021 (last updated February 22, 2025)
Report portal is an open source reporting and analysis framework. Starting from version 3.1.0 of the service-api XML parsing was introduced. Unfortunately the XML parser was not configured properly to prevent XML external entity (XXE) attacks. This allows a user to import a specifically-crafted XML file which imports external Document Type Definition (DTD) file with external entities for extraction of secrets from Report Portal service-api module or server-side request forgery. This will be resolved in the 5.4.0 release.
0
Attacker Value
Unknown
CVE-2021-35066
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
0
Attacker Value
Unknown
CVE-2021-28684
Disclosure Date: June 21, 2021 (last updated February 22, 2025)
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
0
Attacker Value
Unknown
CVE-2021-33813
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2020-5003
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
IBM Financial Transaction Manager 3.2.4 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 192956.
0
Attacker Value
Unknown
CVE-2021-27635
Disclosure Date: June 09, 2021 (last updated February 22, 2025)
SAP NetWeaver AS for JAVA, versions - 7.20, 7.30, 7.31, 7.40, 7.50, allows an attacker authenticated as an administrator to connect over a network and submit a specially crafted XML file in the application because of missing XML Validation, this vulnerability enables attacker to fully compromise confidentiality by allowing them to read any file on the filesystem or fully compromise availability by causing the system to crash. The attack cannot be used to change any data so that there is no compromise as to integrity.
0
Attacker Value
Unknown
CVE-2020-25817
Disclosure Date: June 08, 2021 (last updated February 22, 2025)
SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML within unit tests can be vulnerable to XML External Entity (XXE) attacks. When this developer utility is misused for purposes involving external or user submitted data in custom project code, it can lead to vulnerabilities such as XSS on HTML output rendered through this custom code. This is now mitigated by disabling external entities during parsing. (The correct CVE ID year is 2020 [CVE-2020-25817, not CVE-2021-25817]).
0