An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 Se
IBM Engineering Lifecycle Optimization - Engineering Insights 7.0.2 and 7.0.3 is vulnerable to an XML External Entity In
The CycloneDX JavaScript library contains the core functionality of OWASP CycloneDX for JavaScript. In 6.7.0, XML Extern
XXE vulnerability in Liferay Portal 7.2.0 through 7.4.3.7, and older unsupported versions, and Liferay DXP 7.4 before up
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD
Improper Restriction of XML External Entity Reference vulnerability in OpenText Application Automation Tools allows DTD
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to information discl
XML External Entity injection vulnerability found in OpenText™ iManager 3.2.6.0200. This could lead to remote code execu
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
fontTools is a library for manipulating fonts, written in Python. The subsetting module has a XML External Entity Inject
LG Simple Editor saveXmlFile XML External Entity Processing Information Disclosure Vulnerability. This vulnerability all
LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability all
LG Simple Editor copyContent XML External Entity Processing Information Disclosure Vulnerability. This vulnerability all
Voltronic Power ViewPower Pro doDocument XML External Entity Processing Information Disclosure Vulnerability. This vulne
An XML External Entity (XXE) vulnerability in the ebookmeta.get_metadata function of ebookmeta before v1.2.8 allows atta
ClassGraph before 4.8.112 was not resistant to XML eXternal Entity (XXE) attacks.
The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida
The "soap_cgi.pyc" API handler allows the XML body of SOAP requests to contain references to external entities. This all
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on t
An issue was discovered in libexpat before 2.6.3. xmlparse.c does not reject a negative length for XML_ParseBuffer.
DataEase is an open source data visualization analysis tool. Prior to version 2.10.1, there is an XML external entity in
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. The security scanner responsible for pre
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affe
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The XmlScanner class has a scan method which
PhpSpreadsheet is a PHP library for reading and writing spreadsheet files. The `XmlScanner` class has a scan method whic
Possible XML External Entity Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0200
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose in
When the Kiuwan Local Analyzer uploads the scan results to the Kiuwan SAST web application (either on-premises or cloud
IBM Security Access Manager Container (IBM Security Verify Access Appliance 10.0.0.0 through 10.0.6.1 and IBM Security V
The XML document processed in the GMS ECM URL endpoint is vulnerable to XML external entity (XXE) injection, potentially
IBM Engineering Requirements Management DOORS Web Access 9.7.2.8 is vulnerable to an XML External Entity Injection (XXE)
IBM WebSphere Application Server 8.5, 9.0 and IBM WebSphere Application Server Liberty 17.0.0.3 through 24.0.0.5 are vul
The Spreadsheet::ParseXLSX package before 0.30 for Perl allows XXE attacks because it neglects to use the no_xxe option
The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, whi
Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This
Visualware MyConnection Server doIForward XML External Entity Processing Information Disclosure Vulnerability. This vuln
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerabilit
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerabilit
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerabilit
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerabilit
Honeywell Saia PG5 Controls Suite XML External Entity Processing Information Disclosure Vulnerability. This vulnerabilit
Microsoft SharePoint Server Information Disclosure Vulnerability
An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earli
Improper Restriction of XML External Entity Reference vulnerability in PruvaSoft Informatics Apinizer Management Console
Improper Restriction of XML External Entity Reference vulnerability in WP Royal Royal Elementor Addons royal-elementor-a
A blind XML External Entities (XXE) injection vulnerability in the Palo Alto Networks PAN-OS software enables an authent
Frequently Asked Questions
What is CWE-611?
CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-611?
There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.
How can I protect against CWE-611 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.
Detect CWE-611 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.
Get Started