Перейти к содержимому
Noroxi

CWE-91 · 135 записей

XML Injection (aka Blind XPath Injection)

CVE этого класса

135 записей

  • CVE-2020-0646
    99Срочно

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    microsoft · .net framework14 янв. 2020 г.

  • CVE-2023-27253
    62На этой неделе

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 90 %

    netgate · pfsense17 мар. 2023 г.

  • CVE-2023-46214
    62На этой неделе

    Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

    ВысокаяCVSS 8,8Готовый эксплойтEPSS 89 %

    splunk · cloud16 нояб. 2023 г.

  • CVE-2024-53675
    55В плане

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    ВысокаяCVSS 7,5Эксплойта нетEPSS 84 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2023-43187
    53В плане

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers

    КритическаяCVSS 9,8Proof of conceptEPSS 47 %

    nodebb · nodebb27 сент. 2023 г.

  • CVE-2024-53674
    44В плане

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    ВысокаяCVSS 7,5Эксплойта нетEPSS 47 %

    hpe · insight remote support26 нояб. 2024 г.

  • CVE-2019-17626
    42В плане

    ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document

    КритическаяCVSS 9,8Эксплойта нетEPSS 10 %

    reportlab · reportlab16 окт. 2019 г.

  • CVE-2019-14277
    41В плане

    Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injecti

    КритическаяCVSS 9,8Эксплойта нетEPSS 7 %

    axway · securetransport26 июл. 2019 г.

  • CVE-2019-19450
    41В плане

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    reportlab · reportlab20 сент. 2023 г.

  • CVE-2015-6970
    41В плане

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to c

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    boschsecurity · nbn-498 dinion2x day\/night ip cameras firmware18 февр. 2020 г.

  • CVE-2019-16941
    41В плане

    NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E

    КритическаяCVSS 9,8Proof of conceptEPSS 5 %

    nsa · ghidra28 сент. 2019 г.

  • CVE-2021-36020
    40В плане

    Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    adobe · adobe commerce1 сент. 2021 г.

  • CVE-2020-25216
    40В плане

    yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesh

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    yworks · yed17 сент. 2020 г.

  • CVE-2020-29128
    40В плане

    petl before 1.68, in some configurations, allows resolution of entities in an XML document.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    petl project · petl26 нояб. 2020 г.

  • CVE-2020-11535
    40В плане

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    onlyoffice · document server15 апр. 2020 г.

  • CVE-2020-8479
    40В плане

    ABB Central Licensing System - XML External Entity Injection

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    abb · 800xa system28 апр. 2020 г.

  • CVE-2013-7429
    40В плане

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    mapsplugin · googlemaps14 сент. 2017 г.

  • CVE-2021-4140
    40В плане

    It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.

    КритическаяCVSS 10,0Эксплойта нетEPSS 1 %

    mozilla · firefox22 дек. 2022 г.

  • CVE-2013-4857
    39Наблюдать

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    dlink · dir-865l firmware25 окт. 2019 г.

  • CVE-2021-37154
    39Наблюдать

    In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    forgerock · access management25 авг. 2021 г.

  • CVE-2019-8158
    39Наблюдать

    An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    magento · magento5 нояб. 2019 г.

  • CVE-2025-66034
    39Наблюдать

    fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

    КритическаяCVSS 9,8Proof of conceptEPSS 1 %

    fonttools · fonttools28 нояб. 2025 г.

  • CVE-2018-19277
    37Наблюдать

    securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    ВысокаяCVSS 8,8Proof of conceptEPSS 8 %

    phpoffice · phpspreadsheet14 нояб. 2018 г.

  • CVE-2014-1409
    37Наблюдать

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with

    КритическаяCVSS 9,1Эксплойта нетEPSS 4 %

    mobileiron · virtual smartphone platform8 янв. 2020 г.

  • CVE-2021-21019
    37Наблюдать

    Magento Commerce XML Injection Could Lead To Remote Code Execution

    КритическаяCVSS 9,1Эксплойта нетEPSS 4 %

    magento · magento11 февр. 2021 г.

Все классы уязвимостей