Vulnerabilities (CVE)

Filtered by CWE-611
Total 1326 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-46682 1 Jenkins 1 Plot 2026-06-17 N/A 9.8 CRITICAL
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-46300 1 Visam 1 Vbase Automation Base 2026-06-17 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-45876 1 Visam 1 Vbase 2026-06-17 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-45468 1 Visam 1 Vbase Automation Base 2026-06-17 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-45400 1 Jenkins 1 Japex 2026-06-17 N/A 9.8 CRITICAL
Jenkins JAPEX Plugin 1.7 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45397 1 Jenkins 1 Osf Builder Suite \ 2026-06-17 N/A 9.8 CRITICAL
Jenkins OSF Builder Suite : : XML Linter Plugin 1.0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45396 1 Jenkins 1 Sourcemonitor 2026-06-17 N/A 9.8 CRITICAL
Jenkins SourceMonitor Plugin 0.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45395 1 Jenkins 1 Cccc 2026-06-17 N/A 9.8 CRITICAL
Jenkins CCCC Plugin 0.6 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45386 1 Jenkins 1 Violations 2026-06-17 N/A 5.5 MEDIUM
Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45326 1 Kwoksys 1 Information Server 2026-06-17 N/A 4.9 MEDIUM
An XML external entity (XXE) injection vulnerability in Kwoksys Kwok Information Server before v2.9.5.SP31 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks.
CVE-2022-45194 1 Bruhn-newtech 1 Cbrn-analysis 2026-06-17 N/A 3.8 LOW
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
CVE-2022-45121 1 Visam 1 Vbase Automation Base 2026-06-17 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-43941 1 Hitachi 1 Vantara Pentaho Business Analytics Server 2026-06-17 N/A 7.1 HIGH
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x do not correctly protect the Post Analysis service endpoint of the data access plugin against out-of-band XML External Entity Reference. 
CVE-2022-43689 1 Concretecms 1 Concrete Cms 2026-06-17 N/A 5.3 MEDIUM
Concrete CMS (formerly concrete5) below 8.5.10 and between 9.0.0 and 9.1.2 is vulnerable to XXE based DNS requests leading to IP disclosure.
CVE-2022-43570 1 Splunk 2 Splunk, Splunk Cloud Platform 2026-06-17 N/A 8.8 HIGH
In Splunk Enterprise versions below 8.1.12, 8.2.9, and 9.0.2, an authenticated user can perform an extensible markup language (XML) external entity (XXE) injection via a custom View. The XXE injection causes Splunk Web to embed incorrect documents into an error.
CVE-2022-43512 1 Visam 1 Vbase Automation Base 2026-06-17 N/A 5.5 MEDIUM
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
CVE-2022-43473 1 Zohocorp 3 Manageengine Opmanager, Manageengine Opmanager Msp, Manageengine Opmanager Plus 2026-06-17 N/A 5.8 MEDIUM
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
CVE-2022-43430 1 Jenkins 1 Compuware Topaz For Total Test 2026-06-17 N/A 7.5 HIGH
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-43415 1 Jenkins 1 Repo 2026-06-17 N/A 7.5 HIGH
Jenkins REPO Plugin 1.15.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-42745 1 Auieosoftware 1 Candidats 2026-06-17 N/A 7.5 HIGH
CandidATS version 3.0.0 allows an external attacker to read arbitrary files from the server. This is possible because the application is vulnerable to XXE.