Show filters
229 Total Results
Displaying 41-50 of 229
Sort by:
Attacker Value
Unknown
CVE-2021-39371
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
0
Attacker Value
Unknown
CVE-2020-18703
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/utils/atom.py'.
0
Attacker Value
Unknown
CVE-2020-18705
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
XML External Entities (XXE) in Quokka v0.4.0 allows remote attackers to execute arbitrary code via the component 'quokka/core/content/views.py'.
0
Attacker Value
Unknown
CVE-2021-34823
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The ON24 ScreenShare (aka DesktopScreenShare.app) plugin before 2.0 for macOS allows remote file access via its built-in HTTP server. This allows unauthenticated remote users to retrieve files accessible to the logged-on macOS user. When a remote user sends a crafted HTTP request to the server, it triggers a code path that will download a configuration file from a specified remote machine over HTTP. There is an XXE flaw in processing of this configuration file that allows reading local (to macOS) files and uploading them to remote machines.
0
Attacker Value
Unknown
CVE-2021-27741
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
" Security vulnerability in HCL Commerce Management Center allowing XML external entity (XXE) injection"
0
Attacker Value
Unknown
CVE-2021-38584
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
0
Attacker Value
Unknown
CVE-2021-37425
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
Altova MobileTogether Server before 7.3 SP1 allows XXE attacks, such as an InfoSetChanges/Changes attack against /workflowmanagement, or reading mobiletogetherserver.cfg and then reading the certificate and private key.
0
Attacker Value
Unknown
CVE-2021-37178
Disclosure Date: August 10, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted xml file.
0
Attacker Value
Unknown
CVE-2021-1630
Disclosure Date: August 05, 2021 (last updated February 23, 2025)
XML external entity (XXE) vulnerability affecting certain versions of a Mule runtime component that may affect CloudHub, GovCloud, Runtime Fabric, Pivotal Cloud Foundry, Private Cloud Edition, and on-premise customers.
0
Attacker Value
Unknown
CVE-2020-26564
Disclosure Date: July 31, 2021 (last updated February 23, 2025)
ObjectPlanet Opinio before 7.15 allows XXE attacks via three steps: modify a .css file to have <!ENTITY content, create a .xml file for a generic survey template (containing a link to this .css file), and import this .xml file at the survey/admin/folderSurvey.do?action=viewImportSurvey['importFile'] URI. The XXE can then be triggered at a admin/preview.do?action=previewSurvey&surveyId= URI.
0