CWE-91 · 135 kayıt
XML Injection (aka Blind XPath Injection)
Bu sınıftaki CVE’ler
135 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2020-0646Silahlaştırılmış | A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote microsoft · .net framework · CWE-91 | Kritik9,8 | KEV | %99,2 | 14 Oca 2020 |
62Bu hafta | CVE-2023-27253Silahlaştırılmış | A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbinetgate · pfsense · CWE-91 | Yüksek8,8 | — | %89,5 | 17 Mar 2023 |
62Bu hafta | CVE-2023-46214Silahlaştırılmış | Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsingsplunk · cloud · CWE-91 | Yüksek8,8 | — | %89,2 | 16 Kas 2023 |
55Planlayın | CVE-2024-53675İstismar yok | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Yüksek7,5 | — | %83,6 | 26 Kas 2024 |
53Planlayın | CVE-2023-43187Kavram kanıtı | A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackersnodebb · nodebb · CWE-91 | Kritik9,8 | — | %47,4 | 27 Eyl 2023 |
44Planlayın | CVE-2024-53674İstismar yok | An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certainhpe · insight remote support · CWE-91 | Yüksek7,5 | — | %46,7 | 26 Kas 2024 |
42Planlayın | CVE-2019-17626İstismar yok | ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document reportlab · reportlab · CWE-91 | Kritik9,8 | — | %10,2 | 16 Eki 2019 |
41Planlayın | CVE-2019-14277İstismar yok | Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injectiaxway · securetransport · CWE-91 | Kritik9,8 | — | %7,3 | 26 Tem 2019 |
41Planlayın | CVE-2019-19450İstismar yok | paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in reportlab · reportlab · CWE-91 | Kritik9,8 | — | %6,0 | 20 Eyl 2023 |
41Planlayın | CVE-2015-6970Kavram kanıtı | The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to cboschsecurity · nbn-498 dinion2x day\/night ip cameras firmware · CWE-91 | Kritik9,8 | — | %5,3 | 18 Şub 2020 |
41Planlayın | CVE-2019-16941Kavram kanıtı | NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns Ensa · ghidra · CWE-91 | Kritik9,8 | — | %5,1 | 28 Eyl 2019 |
40Planlayın | CVE-2021-36020İstismar yok | Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Executionadobe · adobe commerce · CWE-91 | Kritik9,8 | — | %2,7 | 1 Eyl 2021 |
40Planlayın | CVE-2020-25216İstismar yok | yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom styleshyworks · yed · CWE-91 | Kritik9,8 | — | %2,4 | 17 Eyl 2020 |
40Planlayın | CVE-2020-29128İstismar yok | petl before 1.68, in some configurations, allows resolution of entities in an XML document.petl project · petl · CWE-91 | Kritik9,8 | — | %2,3 | 26 Kas 2020 |
40Planlayın | CVE-2020-11535İstismar yok | An issue was discovered in ONLYOFFICE Document Server 5.5.0.onlyoffice · document server · CWE-91 | Kritik9,8 | — | %2,3 | 15 Nis 2020 |
40Planlayın | CVE-2020-8479İstismar yok | ABB Central Licensing System - XML External Entity Injectionabb · 800xa system · CWE-91 | Kritik9,8 | — | %2,3 | 28 Nis 2020 |
40Planlayın | CVE-2013-7429İstismar yok | The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemapsplugin · googlemaps · CWE-91 | Kritik9,8 | — | %2,2 | 14 Eyl 2017 |
40Planlayın | CVE-2021-4140İstismar yok | It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.mozilla · firefox · CWE-91 | Kritik10,0 | — | %1,3 | 22 Ara 2022 |
39İzleyin | CVE-2013-4857İstismar yok | D-Link DIR-865L has PHP File Inclusion in the router xml file.dlink · dir-865l firmware · CWE-91 | Kritik9,8 | — | %1,6 | 25 Eki 2019 |
39İzleyin | CVE-2021-37154İstismar yok | In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0 forgerock · access management · CWE-91 | Kritik9,8 | — | %1,4 | 25 Ağu 2021 |
39İzleyin | CVE-2019-8158İstismar yok | An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.magento · magento · CWE-91 | Kritik9,8 | — | %1,3 | 5 Kas 2019 |
39İzleyin | CVE-2025-66034Kavram kanıtı | fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLibfonttools · fonttools · CWE-91 | Kritik9,8 | — | %0,5 | 28 Kas 2025 |
37İzleyin | CVE-2018-19277Kavram kanıtı | securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx filephpoffice · phpspreadsheet · CWE-91 | Yüksek8,8 | — | %7,8 | 14 Kas 2018 |
37İzleyin | CVE-2014-1409İstismar yok | MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with mobileiron · virtual smartphone platform · CWE-91 | Kritik9,1 | — | %4,0 | 8 Oca 2020 |
37İzleyin | CVE-2021-21019İstismar yok | Magento Commerce XML Injection Could Lead To Remote Code Executionmagento · magento · CWE-91 | Kritik9,1 | — | %3,6 | 11 Şub 2021 |
- CVE-2020-064699Hemen
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99microsoft · .net framework14 Oca 2020
- CVE-2023-2725362Bu hafta
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbi
YüksekCVSS 8,8SilahlaştırılmışEPSS %90netgate · pfsense17 Mar 2023
- CVE-2023-4621462Bu hafta
Remote code execution (RCE) in Splunk Enterprise through Insecure XML Parsing
YüksekCVSS 8,8SilahlaştırılmışEPSS %89splunk · cloud16 Kas 2023
- CVE-2024-5367555Planlayın
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
YüksekCVSS 7,5İstismar yokEPSS %84hpe · insight remote support26 Kas 2024
- CVE-2023-4318753Planlayın
A remote code execution (RCE) vulnerability in the xmlrpc.php endpoint of NodeBB Inc NodeBB forum software prior to v1.18.6 allows attackers
KritikCVSS 9,8Kavram kanıtıEPSS %47nodebb · nodebb27 Eyl 2023
- CVE-2024-5367444Planlayın
An XML external entity injection (XXE) vulnerability in HPE Insight Remote Support may allow remote users to disclose information in certain
YüksekCVSS 7,5İstismar yokEPSS %47hpe · insight remote support26 Kas 2024
- CVE-2019-1762642Planlayın
ReportLab through 3.5.26 allows remote code execution because of toColor(eval(arg)) in colors.py, as demonstrated by a crafted XML document
KritikCVSS 9,8İstismar yokEPSS %10reportlab · reportlab16 Eki 2019
- CVE-2019-1427741Planlayın
Axway SecureTransport 5.x through 5.3 (or 5.x through 5.5 with certain API configuration) is vulnerable to unauthenticated blind XML injecti
KritikCVSS 9,8İstismar yokEPSS %7axway · securetransport26 Tem 2019
- CVE-2019-1945041Planlayın
paraparser in ReportLab before 3.5.31 allows remote code execution because start_unichar in paraparser.py evaluates untrusted user input in
KritikCVSS 9,8İstismar yokEPSS %6reportlab · reportlab20 Eyl 2023
- CVE-2015-697041Planlayın
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to c
KritikCVSS 9,8Kavram kanıtıEPSS %5boschsecurity · nbn-498 dinion2x day\/night ip cameras firmware18 Şub 2020
- CVE-2019-1694141Planlayın
NSA Ghidra through 9.0.4, when experimental mode is enabled, allows arbitrary code execution if the Read XML Files feature of Bit Patterns E
KritikCVSS 9,8Kavram kanıtıEPSS %5nsa · ghidra28 Eyl 2019
- CVE-2021-3602040Planlayın
Magento Commerce XML Injection Vulnerability In The 'City' Field Could Lead To Remote Code Execution
KritikCVSS 9,8İstismar yokEPSS %3adobe · adobe commerce1 Eyl 2021
- CVE-2020-2521640Planlayın
yWorks yEd Desktop before 3.20.1 allows code execution via an XSL Transformation when using an XML file in conjunction with a custom stylesh
KritikCVSS 9,8İstismar yokEPSS %2yworks · yed17 Eyl 2020
- CVE-2020-2912840Planlayın
petl before 1.68, in some configurations, allows resolution of entities in an XML document.
KritikCVSS 9,8İstismar yokEPSS %2petl project · petl26 Kas 2020
- CVE-2020-1153540Planlayın
An issue was discovered in ONLYOFFICE Document Server 5.5.0.
KritikCVSS 9,8İstismar yokEPSS %2onlyoffice · document server15 Nis 2020
- CVE-2020-847940Planlayın
ABB Central Licensing System - XML External Entity Injection
KritikCVSS 9,8İstismar yokEPSS %2abb · 800xa system28 Nis 2020
- CVE-2013-742940Planlayın
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_google
KritikCVSS 9,8İstismar yokEPSS %2mapsplugin · googlemaps14 Eyl 2017
- CVE-2021-414040Planlayın
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.
KritikCVSS 10,0İstismar yokEPSS %1mozilla · firefox22 Ara 2022
- CVE-2013-485739İzleyin
D-Link DIR-865L has PHP File Inclusion in the router xml file.
KritikCVSS 9,8İstismar yokEPSS %2dlink · dir-865l firmware25 Eki 2019
- CVE-2021-3715439İzleyin
In ForgeRock Access Management (AM) before 7.0.2, the SAML2 implementation allows XML injection, potentially enabling a fraudulent SAML 2.0
KritikCVSS 9,8İstismar yokEPSS %1forgerock · access management25 Ağu 2021
- CVE-2019-815839İzleyin
An XPath entity injection vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1.
KritikCVSS 9,8İstismar yokEPSS %1magento · magento5 Kas 2019
- CVE-2025-6603439İzleyin
fontTools is Vulnerable to Arbitrary File Write and XML injection in fontTools.varLib
KritikCVSS 9,8Kavram kanıtıEPSS %1fonttools · fonttools28 Kas 2025
- CVE-2018-1927737İzleyin
securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file
YüksekCVSS 8,8Kavram kanıtıEPSS %8phpoffice · phpspreadsheet14 Kas 2018
- CVE-2014-140937İzleyin
MobileIron VSP versions prior to 5.9.1 and Sentry versions prior to 5.0 have an authentication bypass vulnerability due to an XML file with
KritikCVSS 9,1İstismar yokEPSS %4mobileiron · virtual smartphone platform8 Oca 2020
- CVE-2021-2101937İzleyin
Magento Commerce XML Injection Could Lead To Remote Code Execution
KritikCVSS 9,1İstismar yokEPSS %4magento · magento11 Şub 2021