CWE-611 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-611 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-34102Adobe Commerce versions 2.4.7, 2.4.6-p5, 2.4.5-p7, 2.4.4-p8 and earlier are affected by an Improper …100.0%심각9.8● 실제 악용이 확인됨CVE-2019-9670mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External …100.0%심각9.8● 실제 악용이 확인됨CVE-2025-2776SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vu…64.7%심각9.8● 실제 악용이 확인됨CVE-2025-58360GeoServer is an open source server that allows users to share and edit geospatial data. From version…60.5%심각9.8● 실제 악용이 확인됨CVE-2025-2775SysAid On-Prem versions <= 23.3.40 are vulnerable to an unauthenticated XML External Entity (XXE) vu…42.6%높음7.5● 랜섬웨어 캠페인에 사용됨CVE-2019-13608Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0…30.0%높음7.5● 실제 악용이 확인됨CVE-2016-9563BC-BMT-BPM-DSK in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML Externa…24.2%보통6.5● 실제 악용이 확인됨CVE-2023-45727Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier…3.5%높음7.5
전체 목록
49건
CVE-2026-94108getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function…0.5%높음8.3
CVE-2026-88789Improper Restriction of XML External Entity Reference in the XSLT support extension (camel-quarkus-support-xal…0.5%높음8.6
CVE-2026-12756IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection …0.5%높음7.1
CVE-2026-12752IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection …0.5%높음7.1
CVE-2026-78224The XSLT Transformer Step builds a bare TransformerFactory without the proper security options set, so XXE inj…0.4%높음8.8
CVE-2026-89260MoguBlog through 6.2 contains an XML external entity injection vulnerability in the WeChat callback handler at…0.4%높음8.7
CVE-2026-82578When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a de…0.4%높음8.7
CVE-2026-13287IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.4%높음7.1
CVE-2026-13285IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.4%높음7.1
CVE-2026-12667IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.4%높음7.1
CVE-2026-13107IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulne…0.4%높음7.1
CVE-2026-16432IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage PxXMLInput operator could allow a remote authenticat…0.3%높음7.7
CVE-2026-76427A vulnerability in the offline profiler feed service of Cisco ISE could allow an authenticated, remote attacke…0.3%보통4.9
CVE-2026-61570MPXJ is an open source library to read and write project plans from a variety of file formats and databases. F…0.3%높음7.5
CVE-2026-89212A flaw resulting in XML external entity (XXE) was found in Akana API Platform in which references were imprope…0.3%심각9.2
CVE-2026-79572An XXE (XML External Entity) vulnerability in the level-rule module of Distribution Management v1.0.0 allows a…0.3%높음7.5
CVE-2026-76446A vulnerability in an API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to read…0.3%보통4.9
CVE-2026-17444IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.3%보통5.3
CVE-2026-17443IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.3%보통5.3
CVE-2026-82376Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a user with entry-editing …0.3%높음7.7
CVE-2026-81832IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus …0.3%높음7.7
CVE-2026-61741http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to…0.3%심각9.3
CVE-2026-82386Improper Restriction of XML External Entity Reference in Apache Roller 6.1.5 allows a weblog administrator to …0.3%높음7.7
CVE-2026-84941An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller all…0.3%보통6.9
CVE-2026-17646IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to ob…0.3%높음8.5
CVE-2026-18061Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrap…0.3%보통6.0
CVE-2026-91197Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagr…0.3%높음7.1
CVE-2026-12666IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.3%높음8.1
CVE-2026-93030FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external…0.3%보통6.5
CVE-2026-81536IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive in…0.3%높음7.7
CVE-2026-13275IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.3%높음7.1
CVE-2026-71375Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This is…0.2%높음7.4
CVE-2026-19614The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. T…0.2%보통5.3
CVE-2026-13265IBM MQ 9.1.0.0 through 9.1.0.37 LTS, 9.2.0.0 through 9.2.0.43 LTS, 9.3.0.0 through 9.3.0.41 LTS, 9.3.0.0 throu…0.2%보통6.8
CVE-2026-76958SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain …0.2%높음8.5
CVE-2026-19596An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridia…0.2%보통5.9
CVE-2026-18184IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive…0.2%높음7.4
CVE-2026-18172IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive…0.2%높음7.4
CVE-2026-102127An XML parser used by Kiteworks Email Protection Gateway did not restrict external entity references. Where an…0.2%높음7.0
CVE-2026-82918XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external ent…0.2%보통6.7
CVE-2026-82525Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attack…0.1%보통6.8
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.