xxe
4 articles with this tag
HIGH
MEDIUM
HIGH
MEDIUM
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
Reading /etc/passwd via translation file upload in Tolgee's cloud platform (CVE-2026-32251, CVSS 9.3)
SB2025051940 - Multiple vulnerabilities in Siemens Polarion