İçeriğe atla
Noroxi

CWE-91 · 135 kayıt

XML Injection (aka Blind XPath Injection)

Bu sınıftaki CVE’ler

135 kayıt

  • A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    microsoft · .net framework14 Oca 2020

  • CVE-2023-27253
    62Bu hafta

    A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi

    YüksekCVSS 8,8SilahlaştırılmışEPSS %90

    netgate · pfsense17 Mar 2023

  • CVE-2023-46214
    62Bu hafta

    Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing

    YüksekCVSS 8,8SilahlaştırılmışEPSS %89

    splunk · cloud16 Kas 2023

  • CVE-2024-53675
    55Planlayın

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    YüksekCVSS 7,5İstismar yokEPSS %84

    hpe · insight remote support26 Kas 2024

  • CVE-2023-43187
    53Planlayın

    A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers

    KritikCVSS 9,8Kavram kanıtıEPSS %47

    nodebb · nodebb27 Eyl 2023

  • CVE-2024-53674
    44Planlayın

    An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain

    YüksekCVSS 7,5İstismar yokEPSS %47

    hpe · insight remote support26 Kas 2024

  • CVE-2019-17626
    42Planlayın

    ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document

    KritikCVSS 9,8İstismar yokEPSS %10

    reportlab · reportlab16 Eki 2019

  • CVE-2019-14277
    41Planlayın

    Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injecti

    KritikCVSS 9,8İstismar yokEPSS %7

    axway · securetransport26 Tem 2019

  • CVE-2019-19450
    41Planlayın

    paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in

    KritikCVSS 9,8İstismar yokEPSS %6

    reportlab · reportlab20 Eyl 2023

  • CVE-2015-6970
    41Planlayın

    The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to c

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    boschsecurity · nbn-498 dinion2x day\/night ip cameras firmware18 Şub 2020

  • CVE-2019-16941
    41Planlayın

    NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E

    KritikCVSS 9,8Kavram kanıtıEPSS %5

    nsa · ghidra28 Eyl 2019

  • CVE-2021-36020
    40Planlayın

    Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution

    KritikCVSS 9,8İstismar yokEPSS %3

    adobe · adobe commerce1 Eyl 2021

  • CVE-2020-25216
    40Planlayın

    yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesh

    KritikCVSS 9,8İstismar yokEPSS %2

    yworks · yed17 Eyl 2020

  • CVE-2020-29128
    40Planlayın

    petl before 1.68, in some configurations, allows resolution of entities in an XML document.

    KritikCVSS 9,8İstismar yokEPSS %2

    petl project · petl26 Kas 2020

  • CVE-2020-11535
    40Planlayın

    An issue was discovered in ONLYOFFICE Document Server 5.5.0.

    KritikCVSS 9,8İstismar yokEPSS %2

    onlyoffice · document server15 Nis 2020

  • CVE-2020-8479
    40Planlayın

    ABB Central Licensing System - XML External Entity Injection

    KritikCVSS 9,8İstismar yokEPSS %2

    abb · 800xa system28 Nis 2020

  • CVE-2013-7429
    40Planlayın

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google

    KritikCVSS 9,8İstismar yokEPSS %2

    mapsplugin · googlemaps14 Eyl 2017

  • CVE-2021-4140
    40Planlayın

    It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.

    KritikCVSS 10,0İstismar yokEPSS %1

    mozilla · firefox22 Ara 2022

  • CVE-2013-4857
    39İzleyin

    D-Link DIR-865L has PHP File Inclusion in the router xml file.

    KritikCVSS 9,8İstismar yokEPSS %2

    dlink · dir-865l firmware25 Eki 2019

  • CVE-2021-37154
    39İzleyin

    In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0

    KritikCVSS 9,8İstismar yokEPSS %1

    forgerock · access management25 Ağu 2021

  • CVE-2019-8158
    39İzleyin

    An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.

    KritikCVSS 9,8İstismar yokEPSS %1

    magento · magento5 Kas 2019

  • CVE-2025-66034
    39İzleyin

    fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib

    KritikCVSS 9,8Kavram kanıtıEPSS %1

    fonttools · fonttools28 Kas 2025

  • CVE-2018-19277
    37İzleyin

    securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    YüksekCVSS 8,8Kavram kanıtıEPSS %8

    phpoffice · phpspreadsheet14 Kas 2018

  • CVE-2014-1409
    37İzleyin

    MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with

    KritikCVSS 9,1İstismar yokEPSS %4

    mobileiron · virtual smartphone platform8 Oca 2020

  • CVE-2021-21019
    37İzleyin

    Magento Commerce XML Injection Could Lead To Remote Code Execution

    KritikCVSS 9,1İstismar yokEPSS %4

    magento · magento11 Şub 2021

Tüm zafiyet sınıfları