Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CWE-611

MITRE ↗

CWE-611

259
CRITICAL
556
HIGH
397
MEDIUM
22
LOW
1,259 CVEs · Page 7/26
6.5
CVE-2020-26066

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gai

6.5
CVE-2024-50848

An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldSe

6.5
CVE-2024-49064

Microsoft SharePoint Information Disclosure Vulnerability

6.4
CVE-2021-1483

A vulnerability in the web UI of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to gai

6.3
CVE-2024-2826

A vulnerability classified as problematic was found in lakernote EasyAdmin up to 20240315. This vulnerability affects un

6.3
CVE-2023-49234

An XML external entity (XXE) vulnerability was found in Stilog Visual Planning 8. It allows an authenticated attacker to

6.3
CVE-2024-3930

In versions of Akana API Platform prior to 2024.1.0 a flaw resulting in XML External Entity (XXE) was discovered.

6.3
CVE-2024-49535

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by

5.9
CVE-2024-31139

In JetBrains TeamCity before 2024.03 xXE was possible in the Maven build steps detector

5.9
CVE-2024-6961

RAIL documents are an XML-based format invented by Guardrails AI to enforce formatting checks on LLM outputs. Guardrails

5.9
CVE-2024-56356

In JetBrains TeamCity before 2024.12 insecure XMLParser configuration could lead to potential XXE attack

5.8
CVE-2024-28039

Improper restriction of XML external entity references vulnerability exists in FitNesse all releases, which allows a rem

5.7
CVE-2023-6147

Qualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a secu

5.7
CVE-2023-6149

Qualys Jenkins Plugin for WAS prior to version and including 2.0.11 was identified to be affected by a security flaw, w

5.5
CVE-2024-21765

Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 a

5.5
CVE-2024-21796

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creat

5.5
CVE-2024-22380

Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development

5.5
CVE-2024-1167

When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.

5.5
CVE-2023-25926

IBM Security Guardium Key Lifecycle Manager 3.0, 3.0.1, 4.0, 4.1, and 4.1.1 is vulnerable to an XML External Entity Inje

5.5
CVE-2024-25971

Dell PowerProtect Data Manager, version 19.15, contains an XML External Entity Injection vulnerability. A remote high pr

5.5
CVE-2024-45072

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML External Entity Injection (XXE) attack when process

5.5
CVE-2024-45086

IBM WebSphere Application Server 8.5 and 9.0 is vulnerable to an XML external entity injection (XXE) attack when process

5.5
CVE-2024-20531

A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the und

5.5
CVE-2024-49704

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10

5.3
CVE-2024-47582

Due to missing validation of XML input, an unauthenticated attacker could send malicious input to an endpoint which lead

5.1
CVE-2024-54005

A vulnerability has been identified in COMOS V10.3 (All versions < V10.3.3.5.8), COMOS V10.4.0 (All versions), COMOS V10

5.0
CVE-2024-45745

TopQuadrant TopBraid EDG before version 8.0.1 allows an authenticated attacker to upload an XML DTD file and execute Jav

4.9
CVE-2023-4554

Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Serv

4.6
CVE-2024-28198

OpenOlat is an open source web-based e-learning platform for teaching, learning, assessment and communication. By manual

4.3
CVE-2024-21048

Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: XML input

4.3
CVE-2024-40075

Laravel v11.x was discovered to contain an XML External Entity (XXE) vulnerability.

2.9
CVE-2024-39586

Dell AppSync Server, version 4.3 through 4.6, contains an XML External Entity Injection vulnerability. An adjacent high

2.7
CVE-2024-25129

The CodeQL CLI repo holds binaries for the CodeQL command line interface (CLI). Prior to version 2.16.3, an XML parser u

CVE-2024-8602

When the XML is read from the codes in the PDF and parsed using a DocumentBuilder, the default settings of the DocumentB

CVE-2024-10218

XSS Attack in mar.jar, Monitoring Archive Utility (MAR Utility), monitoringconsolecommon.jar in TIBCO Software Inc TIBCO

CVE-2024-9044

A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across mu

CVE-2024-52800

veraPDF is an open source PDF/A validation library. Executing policy checks using custom schematron files via the CLI in

CVE-2024-52596

SimpleSAMLphp xml-common is a common classes for handling XML-structures. When loading an (untrusted) XML document, for

CVE-2021-22501

Improper Restriction of XML External Entity Reference vulnerability in OpenText™ Operations Bridge Manager allows Input

10.0
CVE-2022-22486

IBM Tivoli Workload Scheduler 9.4, 9.5, and 10.1 is vulnerable to an XML External Entity Injection (XXE) attack when pro

9.9
CVE-2023-27874

IBM Aspera Faspex 4.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remot

9.8
CVE-2023-24429

Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents

9.8
CVE-2023-24430

Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XX

9.8
CVE-2023-24441

Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

9.8
CVE-2023-24443

Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (

9.8
CVE-2022-47873

Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).

9.8
CVE-2023-24189

An XML External Entity (XXE) vulnerability in urule v2.1.7 allows attackers to execute arbitrary code via uploading a cr

9.8
CVE-2023-20918

In getPendingIntentLaunchFlags of ActivityOptions.java, there is a possible elevation of privilege due to a confused dep

9.8
CVE-2023-32567

Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

9.8
CVE-2022-48565

An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity

Frequently Asked Questions

What is CWE-611?

CWE-611 (CWE-611) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-611?

There are 1,556 CVE records associated with CWE-611 in our database. Of these, 259 are critical severity, 556 are high severity, and 397 are medium severity.

How can I protect against CWE-611 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-611 using AI-powered security agents.

Detect CWE-611 Vulnerabilities

CyberStrike's AI agents automatically detect cwe-611 vulnerabilities across your infrastructure.

Get Started